Flagship course · 6 modules · Live cohort

PCI DSS Readiness Workshop

A practical program for fintech teams who need PCI readiness audits to feel like a controlled process—not a scramble of screenshots the week before the assessor arrives.

Team collaborating during a readiness workshop

Learning outcomes

  • Produce a scoped CDE diagram your engineers and compliance lead both recognize.
  • Build an evidence pack index with owners, systems, and refresh triggers.
  • Explain logging and access review controls without relying on vendor marketing language.
  • Identify third-party gaps that commonly stall fintech readiness timelines in Korea.
  • Rehearse assessor interviews with retrieval paths instead of memorized slogans.

Informational pricing

Listed for planning only—no checkout on this site.

₩2,450,000 per seat

Includes live sessions, templates, and one post-cohort office hour. Team packs are discussed on the pricing page.

Modules

1. Payment flow archaeology

Trace where primary account numbers, tokens, and sensitive authentication data actually move across your apps, partners, and logs.

2. Scope boundaries that hold

Test segmentation claims against cloud shared services, admin jump hosts, and monitoring tooling that quietly expand the CDE.

3. Evidence pack craft

Assemble control narratives with artifacts assessors can follow—configs, tickets, sampling logic—without drowning reviewers in noise.

4. People, access, and change

Connect joiner-mover-leaver records, privileged access reviews, and change tickets to the controls they supposedly prove.

5. Third parties and processors

Map responsibility matrices for gateways, wallet partners, and SOC providers common in Korean fintech stacks.

6. Assessor interview rehearsal

Practice answering follow-ups under time pressure, including the awkward ones about incomplete compensating controls.

Instructor

Portrait of instructor Haeun Choi

Haeun Choi

Haeun has guided payment and lending teams through readiness cycles with QSAs and internal audit counterparts. She focuses on translating control language into engineering work that can be demonstrated, not merely described.

Learners say

Module three’s evidence index stopped our team from dumping entire Jira exports into the assessor portal. We still spend time gathering samples, but at least the story is coherent.

Junho · Compliance · Seoul
★★★★☆

Strong on third-party mapping. I wished we had one more hour on logging pipelines, though—the rehearsal module moved fast there.

Anonymous client in consumer lending

FAQ

Who should attend?

Security engineers, compliance leads, and a product or platform owner who can speak to payment flows. Pure legal attendees without system access struggle with the labs.

Is this a certification course?

No. It prepares teams for PCI readiness audits; it does not replace QSA services or issue PCI certificates.

What is a real limitation of this workshop?

We cannot remediate your environment for you. If critical logging or segmentation work is incomplete, the cohort will surface that clearly—but fixing infrastructure still sits with your engineers and vendors.

Do you support Korean-language materials?

Live sessions and primary materials are in English. Glossaries include common Korean payment terms where they help avoid mistranslation of control language.