Is PCI DSS Mandatory in India?

By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.Yes. PCI DSS compliance is mandatory for any organisation in India that stores, processes or transmits payment card data.The RBI mandateThe Reserve Bank of India specifically...

PCI DSS 12 Requirements Explained

By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.PCI DSS v4.0 is built on 12 requirements that protect cardholder data. Here is what each group covers.The six goals and 12 requirementsThe requirements span building a secure...

PCI DSS Certification Cost in India

By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.The cost of PCI DSS certification in India depends on your cardholder data environment, transaction volume and validation level. This guide explains the drivers.What PCI DSS cost...

SOC 2 Trust Services Criteria Explained

By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.SOC 2 evaluates your controls against the AICPA Trust Services Criteria. There are five criteria, and you choose which apply to your service.The five criteriaSecurity is...

SOC 2 vs ISO 27001

By Murty Nisthala, CISA, CISSP, CCSP. Reviewed by Girija Togarati, ISO 27001 Lead Auditor.SOC 2 and ISO 27001 both prove strong information security, but they differ. SOC 2 is an attestation report under AICPA criteria. ISO 27001 is a certifiable international...