PCI Publishes Guidance On Security Awareness Training



credit_card_swipeThe Payment Card Industry Council thinks Security Awareness Training is so important that they just published a 25-page guidance paper that fully explains the why, how and what of awareness training programs. And they start out with: "In order for an organization to comply with PCI DSS Requirement 12.6, a formal security awareness program must be in place."

The PCI Security Standards Council was founded in 2006 by payment card companies American Express, MasterCard, Visa, Discover and JCB International, and was tasked with educating merchants, and other involved parties handling cardholder data, on the PCI Data Security Standard (PCI DSS), so that compliance could and would be enforced easier.

Troy Leach, the CTO of PCI SSC, said in a statement. "PCI Standards emphasize the importance of people, process and technology when it comes to protecting payment information. This guidance can help businesses focus on the 'people' part of the equation and build a greater culture of security awareness and vigilance across their organizations.”

I was happy to read it, because they got it totally right. The PCI council took their time, discussed with their Special Interest Group (SIG) and came out with a well thought-through, measured and actionable guide; which helps you to get a program in place.

One section highlights the whole message: "One of the biggest risks to an organization’s information security is often not a weakness in the technology control environment. Rather it is the action or inaction by employees and other personnel that can lead to security incidents for example, through disclosure of information that could be used in a social engineering
attack, not reporting observed unusual activity, accessing sensitive information unrelated to the user’s role without following the proper procedures, and so on."

It was encouraging to see that using KnowBe4's Kevin Mitnick Security Awareness Training program, you can fully comply with the PCI requirements. Here is the PDF, downloadable from KnowBe4's content delivery network at Amazon Web Services.


Request A Demo: Compliance Plus

Old-school compliance training is challenging for organizations to offer, difficult to do right, and is generally very expensive to deliver. In this live one-on-one demo we will show you how easy it is to deliver your compliance training program using Compliance Plus with KnowBe4's training platform.

CMP-Collage-LCompliance Plus gives you:

  • A whole new library with fresh compliance content updated regularly
  • Coverage of legislative requirements, such as HIPAA and many others
  • New-school high-quality customizable modules
  • Short, interactive modules to keep learners focused, newsletters, docs, and posters are all included
  • Completely automated compliance training campaigns with world-class support and extensive reporting

See for yourself how Compliance Plus can help you keep your users on their toes with compliance, risk and workplace safety top of mind!

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://info.knowbe4.com/compliance-plus-demo



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews