PCI DSS in Practice: Scoping, SAQs and Compensating Controls
PCI DSS gets expensive when scope grows unchecked. Shrink the cardholder data environment, pick the right SAQ and document compensating controls that hold up.
What you'll be able to do
- Map your cardholder data environment and shrink it where you can
- Pick the right Self-Assessment Questionnaire and justify it
- Write a compensating control worksheet that holds up
- Avoid the scoping mistakes that pull the whole network into PCI
A PCI scope diagram and SAQ rationale
What's in it. A cardholder data environment scope diagram, SAQ selection rationale and a compensating control worksheet.
You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.
Who it's for
Security and compliance staff at merchants and service providers that handle card data.
What's inside
- Part 1Where the requirement comes from 16 min
- Part 2How small teams and enterprises meet it 15 min
- Part 3The method, step by step 18 min
- Part 4Hands-on lab: small team choose one 60 min
- Part 5Hands-on lab: enterprise choose one 90 min
- Part 6Finish and submit your deliverable 16 min
Built for your size
The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.
How you earn the certificate
Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.