PCI Credit Card Security Risk Compliance

PCI Credit Card Security Risk Readiness & Compliance for Financial Institutions

Tuesday, April 30, 2024
11:00 am – 12:30 pm Eastern

PCI compliance is no joke. This session will describe the latest updates to the compliance standard, present solutions to common adherence challenges, and provide clear strategies for managing the risk and compliance needs related to credit card security. If some of the nuances might be new to you or need refreshing, consider this convenient opportunity to get the latest information.

AFTER THIS WEBINAR YOU’LL BE ABLE TO:

  • Explain how the core elements of the PCI DSS apply to financial institutions
  • Define key challenges in managing a PCI compliance program
  • Describe how to determine and define the scope of a PCI Cardholder Data Environment (CDE)
  • Distinguish between PCI controls that are the responsibility of third-party service providers (TPSPs) and controls that are the responsibility of the financial institution
  • Explain how a well-functioning PCI compliance program can support and enhance an institution’s risk management program

WEBINAR DETAILS 

The PCI DSS (Payment Card Industry Data Security Standard) has been in place for over 15 years. In that time, the standard has had three major revisions, including the release of version 4 in the first quarter of 2022. Financial institutions find themselves functioning in multiple roles: card issuers, acquirers, merchants, and service providers. This session will address common misconceptions and challenges seen in financial institutions including: 

  • “The card data is all encrypted, so we don’t have to worry about it.”
  • “We outsource to XYZ so we are not responsible for compliance.”
  • “No one has asked us for a compliance report.” 
  • “We can’t make the core system compliant so there is no point in the rest of it.”
  • “There is no electronic card holder data in our VoIP system or our data warehouse or…”

WHO SHOULD ATTEND? 

PCI compliance is a business issue, not solely an IT issue. This informative session is designed for people with responsibility and oversight in the following areas: risk management, internal audit, vendor management, card services, IT and cyber operations, and risk management and compliance.

TAKE-AWAY TOOLKIT

  • Schedule of required periodic PCI compliance activities
  • List of required evidentiary documents for PCI compliance 
  • PCI CDE scope analysis flowchart
  • Excel framework mapping tool for alignment of PCI controls with other compliance frameworks such as FFIEC
  • Links to important resources
  • Employee training log 
  • Interactive quiz
  • PDF of slides and speaker’s contact info for follow-up questions
  • Attendance certificate provided to self-report CE credits

SPEAKER

Randall J. Romes, CISSP, CRISC, CISA, MCP, PCI-QSA, CLA

Randy Romes has been a cybersecurity consultant at CLA since 1999 and brings a strong background in computer technology, physics, and education.  As a Principal in the Information Security Services and Financial Services Group, Randy leads a team of technology and industry specialists and is responsible for the continuing development of the open-source, Unix, and Windows applications used in security audits. 

Randy has been involved in developing numerous leading-edge hacking/testing methods and security service offerings.  A featured speaker at national information and security management conferences, Randy holds multiple certifications, a Master’s in Educational Technology from the University of Saint Thomas, and a Bachelor’s in Education from the University of Wisconsin – Madison.  In addition, he is an instructor at the CUNA Management School and Graduate School of Banking at the University of Colorado in Boulder.

Attendance verification for CE credits provided upon request.

Webinar Sponsored by Financial Education & Development

If you are having issues with registering online, please contact CBAO's Education, Training & Special Events Coordinator, Malia Widder, (614) 610-1877.

Registration Options (Member/Non-Member Pricing)
Live Webinar ($265/$400) – The live webinar option allows you to have unlimited connections within your institution to virtually attend the Live Webinar. The session includes question and answer sessions, handout and take-away toolkit, and the presenters contact information for follow-up, will all be emailed to you the morning of the live webinar.

On-Demand Webinar + Free Digital Download ($295/$450
– Can’t attend the live webinar? This option provides a recording of the live event, including audio, visuals, and handouts. We even provide the presenter’s email address for follow-up questions. You will receive an email with the recorded webinar link, which can be viewed anytime 24/7, beginning 2 business days after the live webinar. You will also receive instruction on how to download a free digital copy of the webinar to your PC, which you may keep and use indefinitely.

Both Live Webinar & On-Demand Webinar + Free Digital Download ($395/$600
– Includes Live Webinar and Recorded Webinar options above.

When
4/30/2024

Sign In