<?xml version="1.0" standalone="no" ?>

<!--  AIT_PCI_DSS.xml Course Outline in XML format
 *
 * Copyright 2012 Affinity IT Training, LLC. All Rights Reserved.
 *
 -->

<!DOCTYPE FAI:CourseOutline SYSTEM "FAI_CourseOutline.dtd">

<?xml-stylesheet type="text/xsl" href="FAI_CourseOutline.xsl" ?>	

<FAI:CourseOutline FAI:link="AIT_PCI_DSS.xml"
     xmlns:FAI="http://www.fisher-assoc.com/DTDs/FAI_CourseOutline.dtd" >

  <FAI:CourseTitle FAI:level="Introduction"  FAI:code="PCIDSS">
	Understanding the Payment Card Industry Data Security Standard (PCI DSS)
  </FAI:CourseTitle>  
  
  <FAI:CourseCategory>CyberSec</FAI:CourseCategory>
     
  <FAI:SummaryInfo>

    <FAI:CourseDesc FAI:version="Jul10">
    	The PCI DSS is designed to protect credit card users from the unwanted exposure
    	of card holder data and sensitive information.
    	It defines required and suggested requirements for organizations that store, process, or transmit
    	cardholder or related sensitive data.
    	This course explains PCI DSS requirements in the context of the larger framework of IT Security, 
    	and will help organizations understand the motivation for each requirement.
    	Strategies for the successful implementation of each requirement will be examined.    	
   </FAI:CourseDesc>

    <FAI:CourseDuration>
	1 Day
    </FAI:CourseDuration>

    <FAI:CourseAudience>
	Managers and staff of entities that must be PCI DSS compliant.
    </FAI:CourseAudience>

    <FAI:CourseObjectives>

      <FAI:Objective FAI:desc="Understand the purpose and motivation for the PCI DSS" />
      <FAI:Objective FAI:desc="Clearly understand who must comply with PCI DSS" />
      <FAI:Objective FAI:desc="Be familiar with the terms and vocabulary of PCI DSS" />
      <FAI:Objective FAI:desc="Understand the Assessment Process" />
      <FAI:Objective FAI:desc="Be familiar with analyzing the Scope of an Assessment" />
      <FAI:Objective FAI:desc="Be familiar with the content of a Report on Compliance (RoC)" />
      <FAI:Objective FAI:desc="Understand PCI DSS compliance" />
      <FAI:Objective FAI:desc="Be familiar with all PCI DSS Requirements" />
      <FAI:Objective FAI:desc="Understand how to engage a PCI DSS Qualified Security Assessor" />
      
    </FAI:CourseObjectives>

    <FAI:CourseSetupList>
    </FAI:CourseSetupList>    

    <FAI:CourseTextList>
      <FAI:Text FAI:title="Course Workbook" />
    </FAI:CourseTextList>    

    <FAI:CoursePrerequisiteList>
    </FAI:CoursePrerequisiteList>    

  </FAI:SummaryInfo>  

  <FAI:TopicList>                                  

    <FAI:SuperTopic FAI:title="Introduction">
	<FAI:Topic FAI:title="Welcome"/>
	<FAI:Topic FAI:title="Motivation"/>
	<FAI:Topic FAI:title="Objectives"/>
	<FAI:Topic FAI:title="Terms and Concepts"/>
	<FAI:Topic FAI:title="PCI DSS Applicability"/>
	<FAI:Topic FAI:title="PCI DSS Compliance"/>
	<FAI:Topic FAI:title="Course Overview"/>
	<FAI:Topic FAI:title="PCI DSS Requirements Overview"/>
    </FAI:SuperTopic>
    
    <FAI:SuperTopic FAI:title="IT Security Concepts and Terms" >
      <FAI:Topic FAI:title="Malware" />
      <FAI:Topic FAI:title="Vulnerabilities, Threats, and Attacks" />
      <FAI:Topic FAI:title="Vulnerabilities and Threats" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Policies and Procedures" />
      <FAI:Topic FAI:title="Risks and Risk Management" />
      <FAI:Topic FAI:title="Risk Analysis and Mitigation" />
      <FAI:Topic FAI:title="Defense in Depth" />
      <FAI:Topic FAI:title="Security Domains" />
      <FAI:Topic FAI:title="Security vs. Convenience" />
      <FAI:Topic FAI:title="Security Goals" />
      <FAI:Topic FAI:title="Security Resources" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="PCI DSS Requirements" >
      <FAI:SuperTopic FAI:title="Network Security">
	      <FAI:SuperTopic FAI:title="Requirement 1: Install and Maintain a Firewall Configuration...">
	  	    <FAI:Topic FAI:title="Firewall Configuration and Management" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 2: Do Not Use Vendor-supplied Defaults...">
	  	    <FAI:Topic FAI:title="Password and Configuration Management" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Protecting Cardholder Data">
	      <FAI:SuperTopic FAI:title="Requirement 3: Protecting Stored Cardholder Data">
	   	   <FAI:Topic FAI:title="Information Classification and Handling" />
	   	   <FAI:Topic FAI:title="Storage and Encryption" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 4: Encrypt Transmission of Cardholder Data...">
	   	   <FAI:Topic FAI:title="Information Classification and Handling" />
	   	   <FAI:Topic FAI:title="Encrypting Data in Motion" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Maintain a Vulnerability Management Program">
	      <FAI:SuperTopic FAI:title="Requirement 5: Use and Regularly Update Anti-virus Software...">
	 	     <FAI:Topic FAI:title="Anti-Virus Solutions" />
	 	     <FAI:Topic FAI:title="Platform and Application Security" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 6: Develop and Maintain Secure Systems and Applications">
	 	     <FAI:Topic FAI:title="Patch Management" />
	 	     <FAI:Topic FAI:title="Risk and Threat Management" />
	 	     <FAI:Topic FAI:title="Platform and Application Security" />
	 	     <FAI:Topic FAI:title="Change Management" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Implement Strong Access Control Measures">
	      <FAI:SuperTopic FAI:title="Requirement 7: Restrict Access to Cardholder Data...">
	 	     <FAI:Topic FAI:title="Roles and Responsibilities" />
	 	     <FAI:Topic FAI:title="Least Privilege and Permissions Management" />
	 	     <FAI:Topic FAI:title="Access Control Mechanism(s)" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 8: Assign a Unique ID to each Person...">
	 	     <FAI:Topic FAI:title="Account Management" />
	 	     <FAI:Topic FAI:title="Authentication" />
	 	     <FAI:Topic FAI:title="Password Policies" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 9: Restrict Physical Access to Cardholder Data">
	 	     <FAI:Topic FAI:title="Physical Security" />
	 	     <FAI:Topic FAI:title="Monitoring and Logging" />
	 	     <FAI:Topic FAI:title="Information Classification and Handling" />
	 	     <FAI:Topic FAI:title="Information Disposal and Destruction" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Regularly Monitor and Test Networks">
	      <FAI:SuperTopic FAI:title="Requirement 10: Track and Monitor All Access to Network Resources...">
	 	     <FAI:Topic FAI:title="Monitoring and Logging" />
	      </FAI:SuperTopic>
	      <FAI:SuperTopic FAI:title="Requirement 11: Regularly Test Security Systems and Processes">
	 	     <FAI:Topic FAI:title="Testing" />
	 	     <FAI:Topic FAI:title="Penetration Testing" />
	 	     <FAI:Topic FAI:title="Intrusion Detection / Prevention Systems" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Maintain an Information Security Policy">
	      <FAI:SuperTopic FAI:title="Requirement 12: Maintain a Policy That Addresses Information Security...">
	 	     <FAI:Topic FAI:title="Policies and Procedures" />
	 	     <FAI:Topic FAI:title="Roles and Responsibilities" />
	 	     <FAI:Topic FAI:title="Vendor Management" />
	 	     <FAI:Topic FAI:title="Incidence Response" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="The PCI DSS Assessment Process" >
	<FAI:Topic FAI:title="Qualified Security Assessors (QSA)" />
	<FAI:Topic FAI:title="Engaging a QSA" />
	<FAI:SuperTopic FAI:title="Determination of Scope">
		<FAI:Topic FAI:title="Determining Scope" />
		<FAI:Topic FAI:title="Network Segmentation" />
		<FAI:Topic FAI:title="Wireless Access Points" />
		<FAI:Topic FAI:title="Third Party Solutions" />
	</FAI:SuperTopic>
	<FAI:Topic FAI:title="Sampling of Facilities and Systems" />
	<FAI:Topic FAI:title="Compensating Controls" />
	<FAI:Topic FAI:title="Maintaining Compliance" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="The Report on Compliance (RoC)" >
	<FAI:Topic FAI:title="Purpose and Use" />
	<FAI:SuperTopic FAI:title="Report Content">
		<FAI:Topic FAI:title="Executive Summary" />
		<FAI:Topic FAI:title="Scope of Work and Approach Taken" />
		<FAI:Topic FAI:title="Details of Reviewed Environment" />
		<FAI:Topic FAI:title="Contact Information and Report Date" />
		<FAI:Topic FAI:title="Quarterly Scan Results" />
		<FAI:Topic FAI:title="Findings and Observations" />
	</FAI:SuperTopic>
    </FAI:SuperTopic>
    
  </FAI:TopicList>

  <FAI:Appendix FAI:title="Quiz Answers" />
  <FAI:Appendix FAI:title="Additional Resources" />
    
</FAI:CourseOutline>

 
