PCI DSS
Payment Card Industry Data Security Standard. Required of any organization that stores, processes, or transmits cardholder data. The current major version (4.0) tightens authentication requirements and adds MFA for non-console administrative access.
PCI DSS 4.0 pushed authentication requirements up sharply: MFA for all access into the cardholder data environment rather than just remote administrative access, and stronger password rules where passwords remain. For identity teams the practical impact is scoping, since every account that can reach the environment is in scope, including service accounts and vendor support access.
See also: compliance guides, MFA, what is PAM, retail and e-commerce identity
Related on Start with Identity
- GlossaryPSD2
Revised Payment Services Directive. EU regulation requiring Strong Customer Authentication for electronic payments and enabling open banking. SCA mandates two-f
- GuideIdentity Controls for PCI DSS
PCI DSS governs how organizations that handle payment card data protect it, and several of its requirements are squarely about identity. PCI DSS 4.0 raised the
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryFedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used
- GuideGDPR for identity systems: what the regulation actually requires
GDPR confers user rights (access, rectification, erasure, portability, object). Identity systems are usually where those requests are routed because they hold t