ペイメントカード産業データセキュリティ基準ハンドブック<br>Payment Card Industry Data Security Standard Handbook

個数:

ペイメントカード産業データセキュリティ基準ハンドブック
Payment Card Industry Data Security Standard Handbook

  • 在庫がございません。海外の書籍取次会社を通じて出版社等からお取り寄せいたします。
    通常6~9週間ほどで発送の見込みですが、商品によってはさらに時間がかかることもございます。
    重要ご説明事項
    1. 納期遅延や、ご入手不能となる場合がございます。
    2. 複数冊ご注文の場合、分割発送となる場合がございます。
    3. 美品のご指定は承りかねます。
  • 【入荷遅延について】
    世界情勢の影響により、海外からお取り寄せとなる洋書・洋古書の入荷が、表示している標準的な納期よりも遅延する場合がございます。
    おそれいりますが、あらかじめご了承くださいますようお願い申し上げます。
  • ◆画像の表紙や帯等は実物とは異なる場合があります。
  • ◆ウェブストアでの洋書販売価格は、弊社店舗等での販売価格とは異なります。
    また、洋書販売価格は、ご注文確定時点での日本円価格となります。
    ご注文確定後に、同じ洋書の販売価格が変動しても、それは反映されません。
  • 製本 Hardcover:ハードカバー版/ページ数 226 p.
  • 言語 ENG
  • 商品コード 9780470260463
  • DDC分類 332.1788028558

Full Description


Clearly written and easy to use, Payment Card Industry Data Security Standard Handbook is your single source along the journey to compliance with the Payment Card Industry Data Security Standard (PCI DSS), addressing the payment card industry standard that includes requirements for security management, protection of customer account data, policies, procedures, network architecture, software design, and other critical protective measures. This all-inclusive resource facilitates a deeper understanding of how to put compliance into action while maintaining your business objectives.

Contents

Introduction. Part 1History of PCI. Why PCI DSS? Chapter 2: Security 101. Strategy and Planning. Information Risk Management. Information Classifi cation. Risk Assessment. Risk Analysis. Dealing With Risk. Defense in Depth. Policy, Standards, and Procedures. Adoption of a Security Framework. Security and the System Development Life Cycle (SDLC). Security Training and Awareness. Metrics. Physical Security. Data Communications and Networking. Perimeter Security. Information Security Monitoring and Log Management. Intrusion Detection and Intrusion Prevention Technology. Logical Access Control. Electronic Authentication. Encryption. Remote Access Control. Secure Communications. HTTPS. Secure Shell. Virtual Private Networks. Wireless. Incident Response. Forensics. Part 2: PCI Breakdown (Control Objectives and Associated Standards). Chapter 3: Build and Maintain a Secure Network. Requirement 1: Install and Maintain a Firewall Confi guration to Protect Cardholder Data. Requirement 2: Do Not Use Vendor-Supplied Defaults for System Passwords and Other Security Parameters. Requirement A.1: Hosting Providers Protect Cardholder Data Environment. Chapter 4: Protect Cardholder Data. Requirement 3: Protect Stored Cardholder Data. PCI DSS Appendix B: Compensating Controls for Requirement 3.4. Requirement 4: Encrypt Transmission of Cardholder Data Across Open Public Networks. Chapter 5: Maintain a Vulnerability Management Program. Requirement 5: Use and Regularly Update Antivirus Software. Requirement 6: Develop and Maintain Secure Systems and Applications. Chapter 6: Implement Strong Access Control Measures. Requirement 7: Restrict Access to Cardholder Data by Business Need to Know. Requirement 8: Assign a Unique ID to Each Person with Computer Access. Requirement 9: Restrict Physical Access to Cardholder Data. Chapter 7: Regularly Monitor and Test Networks. Requirement 10: Track and Monitor All Access to Network Resources and Cardholder Data. Requirement 11: Regularly Test Security Systems and Processes. Chapter 8: Maintain an Information Security Policy. Requirement 12: Maintain a Policy that Addresses Information Security. Part 3: Strategy and Operations. Chapter 9: Assessment and Remediation. PCI DSS Payment Card Industry Self-Assessment Questionnaire. PCI DSS Security Audit Procedures. PCI DSS Security Scanning Procedures. Leveraging Self-Assessment. Strategy and Program Development. Chapter 10: PCI Program Management. Case for Strategic Compliance. Who Should Be Involved Achieving PCI DSS Compliance for Our Organization? PCI DSS Glossary, Abbreviations, and Acronyms. References. Resources. Index.