PCI DSS

acronym

governance & risksecurity

Stands for: Payment Card Industry Data Security Standard

The payment-card industry's security standard for anyone who stores, processes, or transmits cardholder data.

PCI DSS is set by the PCI Security Standards Council (the card brands) and defines a baseline of network, encryption, access-control, and monitoring requirements. It is contractual rather than governmental, but non-compliance carries fines and lost processing rights. It is a common scope item on vendor trust centers even when the vendor never directly handles card data, because customers deploy their products in cardholder environments.

Also known as: pci dss, pci-dss, pci, cardholder data

All glossary entries