Certified Payment Security Compliance Manager Workshop
Join our CPSCM Workshop for comprehensive training on the entire PCI DSS Suite including PCI DSS, PCI PIN, PCI 3DS, PCI SAQ, UPI, Mobile Wallets and beyond. This comprehensive workshop shapes professionals to unlock expertise in payment security compliance. Secure your role as a leader in the evolving landscape of payment security.
Who Should Attend?
Payment Security Officers
Compliance Managers
Auditors
Risk Management Professionals
Why Attend CPSCM Workshop?
Stay relevant with the latest security trends.
Gain practical knowledge through hands-on workshops.
Enhance your career with a recognized certification.
Connect with industry experts and peers.
Earn 16 CPE credits.
What to Expect From Training?
Building the Foundation
Dive into the background and evolution of the payment industry, understanding the intricacies of payment transaction flows, and exploring the roles and responsibilities of entities within the payment ecosystem. Get acquainted with the various form factors for payment and payment channels, staying up to date with the latest changes in PCI DSS v4.0.1.
Understanding the PCI Suite
Delve into the details of PCI DSS requirements, from data discovery to compensating controls. Explore synergized compliance approach and gain insights into the broader suite of payment standards beyond PCI DSS, including PCI PIN, PCI 3DS, PCI P2PE, PCI CP, SSF, and SWIFT.
Emerging Payment Technologies
Uncover the intricacies of SWIFT, UPI, Mobile Payments, QR Codes, and Contactless Payments. Learn their architectures, security measures, transaction flows, and global adaptability, ensuring a comprehensive understanding of the diverse landscape of modern payment technologies.
Maintaining Compliance
Grasp the nuances of maintaining compliance, the frequency of activities for PCI DSS annual revalidation, and the crucial aspects of report review. Explore the PCI DSS resources and knowledge library, culminating in a practical case study to reinforce your understanding.
Why CPSCM Training Program Is Important?
Comprehensive Understanding
Provides participants with a comprehensive understanding of the payment industry’s intricacies, covering everything from evolution to the latest standards like PCI DSS v4.0.1.
Risk Mitigation and Compliance
By combining risk assessment methodologies and in-depth discussions on control requirements, participants gain the expertise to implement robust security measures.
Adaptability to Emerging Technologies
Goes beyond traditional methods, delving into emerging technologies such as mobile payments, QR codes, and contactless payments.
Industry-Relevant Insights
Led by industry experts, offering insights into roles and responsibilities. Participants gain practical knowledge directly applicable to their professional roles.
Global Perspective
Understanding the global adaptability of payment technologies is crucial. CPSCM equips participants with insights to navigate both local and international ecosystems.
Practical Application
Includes case studies and discussions from a QSA standpoint. Ensures participants are well-versed in theory and equipped to apply knowledge in real-world scenarios.
Benefits of Joining CPSCM Workshop
You will learn from experienced instructors who are experts in payment security compliance.
You will have the opportunity to network with other professionals in payment security compliance.
You will receive access to the latest resources and information on payment security compliance.
What Will You Learn?
Background and Evolution of the Payment Industry
- Elements of the card and importance of card data (Track data, CCV, PAN, PIN)
- Payment transaction flow (Card present and Card not present)
- Stages of payment processing (Authentication, Authorization, Clearing and Settlement)
- Roles and Responsibilities of various entities involved in payment ecosystem
- PCI SSC and responsibilities/differences b/w ISA, QSA, PCI SSC and ASV
Form Factors and PCI DSS v4.0.1
- Various form factors: Cards, Mobile Money, Wearables, Contactless, QR Codes
- What’s new with PCI DSS v4.0.1
- Transition timelines – v3.2.1 to v4.0.1
- Goals and summary of changes
Environments & Risk Assessment
- PCI DSS – On-Prem, Cloud, Shared – What’s Different?
- Type of PCI DSS environments & cloud environment considerations
- Shared Responsibility Matrix
- Risk Assessment: Combination of NIST, OCTAVE, and ISO
- TRA – Targeted Risk Analysis as part of PCI DSS v4.0
SAQ & Implementing PCI DSS (Part 1)
- Self-Assessment Questionnaire (SAQ): Merchant and service provider levels
- Applicability and different types of SAQ
- Implementing PCI DSS requirements (Req 1 To 3) and sub-requirements
- Best practices from a QSA standpoint
- Importance of Data Discovery and other tools
Implementing PCI DSS requirements (Contd.)
- Detailed discussion on Requirement 4 To 12 of PCI DSS and sub-requirements
- Best practices from a QSA standpoint
- Compensating controls
- Differences b/w Defined and Customized approach
- Synergized compliance for PCI DSS
Overview of Payment & PCI Suite
- PCI PIN, PCI 3DS, PCI P2PE, PCI CP, SSF and SWIFT
- Are these standards interrelated?
PCI 3DS & PCI SSF
- PCI 3DS data flow – Architecture review
- ACS, DS and 3DSS
- Overview of the PCI 3DS requirements and dependency on PCI DSS
- PCI SSF: Transition timelines b/w PA DSS and SSF
- Changes b/w PA DSS and SSF
- SSF – S3 and SSLC Applicability
PCI CP (Logical and Physical)
- Architecture review – Layout (Physical and Logical)
- Overview of requirements
SWIFT & UPI
- Different architectures and applicability of SWIFT
- SWIFT – CSCF 2023 framework
- What is UPI, and what are its advantages
- Security behind UPI vs. other form factors of payment
- Sample UPI transaction flow
- Adaptability of UPI across the world
Mobile Payments
- What are mobile payments
- Advantages of mobile payments
- Security of mobile payments
- Sample mobile payment transaction flow
- Global Adaptability of mobile payments
QR Codes
- What are QR Code payments
- Advantages of QR code
- Security of QR code payments
- Sample QR payment transaction flow
- Global Adaptability of QR code payments
Contactless Payments
- What are Contactless payments
- Advantages of Contactless payments
- Security of Contactless payments
- Sample Contactless payment transaction flow
- Global Adaptability of Contactless payment
Compliance Lifecycle
- Requirements overview and summary
- PCI DSS Annual Revalidation – Frequency of activities to be performed
- Report review – ROC and AOC. What to look for?
- PCI DSS resources and knowledge Library
- Case study – PCI DSS