Course Topics:
- PCI DSS and Central Bank Requirements: Approaches to securing payment infrastructure, payment data, and financial services.
- Payment Architecture and the CDE: Defining the card data processing environment, payment perimeter boundaries, PAN data flows, and critical components.
- CDE Segmentation: Network zones, firewall rules, VLANs, microsegmentation, DMZs, and restricting access to the payment perimeter.
- PAN and Sensitive Payment Data Protection: Masking, tokenization, encryption, storage control, and preventing insecure data transmission.
- Secure Configuration of Payment Systems: Hardening servers, POS/e-commerce components, payment gateways, API Gateways, and administrative interfaces.
- Access Management in Payment Infrastructure: RBAC, MFA, PAM/PIM, the Principle of Least Privilege (PoLP), and privileged operation control.
- Cryptographic Protection and Key Management: HSM, KMS, TLS, certificates, key rotation, and access control to cryptographic materials.
- Payment API Security: API Security, OAuth2/OIDC, mTLS, rate limiting, request signing, replay attack protection, and integration control.
- WAF, IDS/IPS, and Perimeter Protection: Traffic filtering, attack detection, and securing e-commerce platforms and public payment services.
- Vulnerability Management: ASV (Approved Scanning Vendor) scanning, internal assessments, vulnerability prioritization, patch management, and remediation verification.
- Penetration Testing and Security Validation: Testing segmentation, payment APIs, web applications, infrastructure, and critical attack scenarios.
- Logging and Monitoring of Payment Operations: Audit logs, SIEM use cases, event correlation, administrative action monitoring, and anomaly detection.
- Anti-Fraud and Transaction Monitoring: Suspicious transaction detection, risk scoring, velocity checks, device fingerprinting, and behavioral analytics.
- Remote Banking Security: Client session control, securing remote banking channels, transaction confirmation, and Account Takeover (ATO) prevention.
- Incident Response for Payment Infrastructure: Triage, investigation, and coordination with acquiring banks, payment brands, and regulators.
- Business Continuity and Resilience: Redundancy, backup/restore, Disaster Recovery (DR), RTO/RPO metrics, and recovery testing.
- Third-Party Risk Management (TPRM): Oversight of processing centers, payment aggregators, cloud providers, contractors, and service organizations.
- Audit Evidence Preparation: Compiling CDE diagrams, access matrices, firewall rules, ASV/PT reports, SIEM logs, cryptographic key policies, and segmentation validation results.