pci-compliance
Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
By wshobson · 9,392 installs
npx skills add wshobson/agents --skill pci-compliance
Source repository · Upstream listing
PCI Compliance
Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.
When to Use This Skill
Building payment processing systems
Handling credit card information
Implementing secure payment flows
Conducting PCI compliance audits
Reducing PCI compliance scope
Implementing tokenization and encryption
Preparing for PCI DSS assessments
PCI DSS Requirements (12 Core Requirements)
Build and Maintain Secure Network
1. Install and maintain firewall configuration
2. Don't use vendor supplied defaults for passwords
Protect Cardholder Data
3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across public networks
Maintain Vulnerability Management
5. Protect systems against malware
6. Develop and maintain secure systems and applications
Implement Strong Access Control
7. Restrict access to cardholder data by business need to know
8. Identify and authenticate access to system components
9. Restrict physical access to cardholder data
Monitor and Test Networks
10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
Maintain Information Security Policy
12. Maintain a policy that addresses information security
Compliance Levels
Level 1 : 6 million transactions/year (annual ROC required)
Level 2 : 1 6 million transactions/year (annual SAQ)
Level 3 : 20,000 1 million e commerce transactions/year
Level 4 : < 20,000 e commerce or < 1 million total transactions
Data Minimization (Never Store)
Tokenization
Using Payment Processor Tokens
Custom Tokenization (Advanced)
Encryption
Data at Rest
Data in Transit
Additional patterns and templates
More detailed templates and worked examples live in references/details.md . Read that file for the full pattern library.