PCI Publishes Guidance On Security Awareness Training

Stu Sjouwerman | Nov 1, 2014

credit_card_swipeThe Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of awareness training programs. And they start out with: "In order for an organization to comply with PCI DSS Requirement 12.6, a formal security awareness program must be in place."

The PCI Security Standards Council was founded in 2006 by payment card companies American Express, MasterCard, Visa, Discover and JCB International, and was tasked with educating merchants, and other involved parties handling cardholder data, on the PCI Data Security Standard (PCI DSS), so that compliance could and would be enforced easier.

Troy Leach, the CTO of PCI SSC, said in a statement. "PCI Standards emphasize the importance of people, process and technology when it comes to protecting payment information. This guidance can help businesses focus on the 'people' part of the equation and build a greater culture of security awareness and vigilance across their organizations.”

I was happy to read it, because they got it totally right. The PCI council took their time, discussed with their Special Interest Group (SIG) and came out with a well thought-through, measured and actionable guide; which helps you to get a program in place.

One section highlights the whole message: "One of the biggest risks to an organization’s information security is often not a weakness in the technology control environment. Rather it is the action or inaction by employees and other personnel that can lead to security incidents for example, through disclosure of information that could be used in a social engineering
attack, not reporting observed unusual activity, accessing sensitive information unrelated to the user’s role without following the proper procedures, and so on."

It was encouraging to see that using KnowBe4's Kevin Mitnick Security Awareness Training program, you can fully comply with the PCI requirements. Here is the PDF, downloadable from KnowBe4's content delivery network at Amazon Web Services.

See Compliance Plus in Action

Learn how easy it is to deliver your compliance training program using Compliance Plus with KnowBe4's training platform.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.