Skip to main content
Course

PCI DSS 4.0 Compliance Essentials

Scope it right, prove it cleanly, and keep it compliant all year, PCI DSS 4.0 without the guesswork.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

5 hours

Estimated time

What you will be able to do

  • You will be able to identify account data, distinguish cardholder data from sensitive authentication data, and apply the storage and masking rules each requires
  • You will be able to define a Cardholder Data Environment and use network segmentation to reduce assessment scope
  • You will be able to group the 12 PCI DSS requirements under their 6 control objectives and explain what each one protects
  • You will be able to choose the correct SAQ type for a merchant and explain when a ROC is required instead
  • You will be able to read an Attestation of Compliance and a Report on Compliance and tell what each one proves
  • You will be able to explain the major PCI DSS 4.0 changes and decide when the customized approach fits
  • You will be able to design a business-as-usual program that keeps controls operating between annual assessments
  • You will be able to recognize the common scoping and maintenance mistakes that cause failed assessments and breaches

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Cardholder Data, the CDE, and Scope

    Start where every PCI DSS project starts: knowing exactly what data the standard protects and where it lives. This module defines account data, the Cardholder Data Environment, and how segmentation shrinks the universe you have to secure and prove.

    2 lessons · 5 quiz questions

  2. 02

    The 12 Requirements and the 6 Control Objectives

    PCI DSS is built from 12 requirements grouped under 6 control objectives. This module walks each objective in plain English so you can place any control in its home and explain what it protects.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Validation: SAQs, the AOC, and the ROC

    Compliance must be proven, and the proof depends on how you accept cards and how much volume you process. This module covers merchant levels, the SAQ types, and the AOC and ROC artifacts that document the result.

    2 lessons · 5 quiz questions

  4. 04

    PCI DSS 4.0 Changes, the Customized Approach, and Staying Compliant

    Version 4.0 brought new controls, a flexible customized approach, and a heavier emphasis on continuous security. This module covers what changed, when the customized approach fits, and how to keep controls operating all year so you don't scramble before each assessment.

    2 lessons · 5 quiz questions · assignment