Module three’s evidence index stopped our team from dumping entire Jira exports into the assessor portal. We still spend time gathering samples, but at least the story is coherent.
PCI DSS Readiness Workshop
A practical program for fintech teams who need PCI readiness audits to feel like a controlled process—not a scramble of screenshots the week before the assessor arrives.
Learning outcomes
- Produce a scoped CDE diagram your engineers and compliance lead both recognize.
- Build an evidence pack index with owners, systems, and refresh triggers.
- Explain logging and access review controls without relying on vendor marketing language.
- Identify third-party gaps that commonly stall fintech readiness timelines in Korea.
- Rehearse assessor interviews with retrieval paths instead of memorized slogans.
Informational pricing
Listed for planning only—no checkout on this site.
₩2,450,000 per seat
Includes live sessions, templates, and one post-cohort office hour. Team packs are discussed on the pricing page.
Modules
1. Payment flow archaeology
Trace where primary account numbers, tokens, and sensitive authentication data actually move across your apps, partners, and logs.
2. Scope boundaries that hold
Test segmentation claims against cloud shared services, admin jump hosts, and monitoring tooling that quietly expand the CDE.
3. Evidence pack craft
Assemble control narratives with artifacts assessors can follow—configs, tickets, sampling logic—without drowning reviewers in noise.
4. People, access, and change
Connect joiner-mover-leaver records, privileged access reviews, and change tickets to the controls they supposedly prove.
5. Third parties and processors
Map responsibility matrices for gateways, wallet partners, and SOC providers common in Korean fintech stacks.
6. Assessor interview rehearsal
Practice answering follow-ups under time pressure, including the awkward ones about incomplete compensating controls.
Instructor
Haeun Choi
Haeun has guided payment and lending teams through readiness cycles with QSAs and internal audit counterparts. She focuses on translating control language into engineering work that can be demonstrated, not merely described.
Learners say
Strong on third-party mapping. I wished we had one more hour on logging pipelines, though—the rehearsal module moved fast there.
FAQ
Who should attend?
Security engineers, compliance leads, and a product or platform owner who can speak to payment flows. Pure legal attendees without system access struggle with the labs.
Is this a certification course?
No. It prepares teams for PCI readiness audits; it does not replace QSA services or issue PCI certificates.
What is a real limitation of this workshop?
We cannot remediate your environment for you. If critical logging or segmentation work is incomplete, the cohort will surface that clearly—but fixing infrastructure still sits with your engineers and vendors.
Do you support Korean-language materials?
Live sessions and primary materials are in English. Glossaries include common Korean payment terms where they help avoid mistranslation of control language.