PCI DSS takes a genuinely different approach to leadership accountability than NIS2, DORA or the UK CAF. PCI DSS doesn't name the board or executive team in a training clause anywhere in the standard. What it does require is executive-level accountability for compliance (and only for service providers), plus training for the personnel who actually handle incidents and cardholder data.

Is Board-Level Cybersecurity Training Required Under PCI DSS?
aditi@cm-alliance.com (Aditi Uberoi)
Tags

