Module 6 · Compliance
ISO 27001 · PCI-DSS
34 / 38

ISO asks for a system. PCI asks for specific controls.

ISO 27001 centers on an ongoing risk-management system; PCI-DSS's highest-leverage move is architectural — never touch raw card data at all.

ISO 27001

An ISMS, not a checklist

An ongoing process of risk assessment and treatment, selecting from ~93 Annex A controls based on your own risk profile.

PCI-DSS

12 requirements, 6 goals

Applies to anyone who stores, processes, or transmits credit card data.

Flat network

Every service can reach the payment component → entire infrastructure in PCI scope.

Segmented + tokenized

Only the payment service touches card data → SAQ A, dramatically less scope.

The cheapest way to comply with PCI-DSS is often architectural: tokenize through a compliant processor and never touch raw card data yourself.