Certified Payment-Card Industry Security Auditor
   HOME

TheInfoList



OR:

Certified Payment-Card Industry Security Auditor (CPISA) is an independent payments industry
certification Certification is part of testing, inspection and certification and the provision by an independent body of written assurance (a certificate) that the product, service or system in question meets specific requirements. It is the formal attestatio ...
governed by the Society of Payment Security Professionals (commonly known as the SPSP). The CPISA focuses on information technology,
information security Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
, and auditing knowledge and skills. This certification is held by members from diverse backgrounds including Level 1 - 4 Merchants, Acquirers, Issuers, QSAs, Processors, Gateways, Service Providers, Consultants, and Auditors. All CPISA holders are members of the SPSP and also hold the CPISM certification.


Certification Knowledge Domains

The CPISA curriculum covers subject matter in a variety of
Information Security Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
and
Payments Industry A payment is the tender of something of value, such as money or its equivalent, by one party (such as a person or company) to another in exchange for goods or services provided by them, or to fulfill a legal obligation or philanthropy desire. Th ...
topics. The CPISA examination is based on what a collection of topics relevant to payment industry security professionals. The CPISA Knowledge Domains establishes a common framework of payment industry terms and definitions that allow security professionals to discuss and debate matters pertaining to the profession with a common understanding. The CPISA Knowledge Domains are:SPSP (CPISA)
/ref>


Requirements

Candidates for the CPISA must meet several requirements: * First, join the Society of Payment Security Professionals * Second, provide a resume with current credentials and two letters of reference from industry professionals. Candidates must also have at least three years of information security or payment industry experience. * Third, one must pass the CPISM and CPISA exams * Upon completion of the exams with a passing grade, the SPSP will issue the CPISA Certificate


Reference Documents

The SPSP provides several reference documents for studying and preparing for the CPISA certification: * CPISA Overview Document * CPISA Study GuideSPSP (CPISA Study Guide)
/ref>


See also

* Certified Payment-Card Industry Security Manager (CPISM) * Certified Payment-Card Industry Security Implementer *
PCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card brands. The standard is administered by the Payment Card Industry Security Standards Council, and its use ...
*
Payment Card Industry The payment card industry (PCI) denotes the debit, credit, prepaid, e-purse, ATM, and POS cards and associated businesses. Overview The payment card industry consists of all the organizations which store, process and transmit cardholder dat ...


External links


PCI Security CouncilPayment Card Industry Fact Sheets


References

{{reflist Payment cards