Training Delivery & Duration

  • Live Online/ On-Site / Private Team
  • Training1 Day

Secure Coding for PCI DSS

The PCI DSS enhances the security of cardholder data. Applications handling payment information must be secure. This course equips developers with the skills to code defensively and meet the secure coding and application security requirements of PCI

Training Delivery & Duration

  • Live Online/ On-Site / Private Team
  • Training1 Day

Do you have 5 or more attendees?

Contact Us about Team Training >>
bkg-decorativelines-big-white

About this course

About this course

Course Overview

The Payment Card Industry Data Security Standard (PCI DSS) enhances cardholder data security. It defines a common set of rules and controls to ensure greater consistency of data security measures. Applications that process card data must be secure. Developers need to understand PCI DSS requirement 6.2.2, how to identify vulnerabilities and how a hacker may try to take advantage of a weakness. Specific knowledge and skills helps developers to code defensively and meet the secure coding and application security standards required by PCI DSS.

Why Take this Course?

  • The Payment Card Industry Data Security Standard (PCI DSS) requires that organisations developing applications that handle card data secure their software against common vulnerabilities. As part of this, PCI DSS compliant organisations that process card payments and/or cardholder data need to train their software developers in secure coding techniques.
  • Our PCI Secure Development training aims to provide developers with an understanding of the issues highlighted in PCI DSS requirement 6.5. They will then get an in-depth review of the various types of threats against systems, and learn the skills required to recognize software vulnerabilities and implement the processes and measures associated with the security development lifecycle (SDL)

Learning Objectives

Who Should Attend this Course?

The course is intended for Developers, Software Engineers, and Software Architects (any level).

Benefits

Attendee Testimonials

Course Outline

The topics covered include:

  • Introduction to PCI DSS Requirements
  • General Application Security Concepts
  • Identify security vulnerabilities in code (OWASP Top 10 - 2025)
    • Broken Access Control
    • Security Misconfiguration
    • Software Supply chain Failures
    • Cryptographic Failures
    • Injection
    • Insecure Design
    • Authentication Failures
    • Software or Data Integrity Failures
    • Logging and Alerting Failures
    • Mishandling of Exceptional Conditions
  • Implement Security Controls
  • Implement the processes and measures associated with the security development lifecycle (SDL).

Duration: 1 day (8 hours)

Format

What is included?

Levels

  • Soft copy of tools & presentation slides
  • Certificate of Participation (CPE Points)

Team Training with Cycubix

Team Training with Cycubix

Instructors

The minds behind the course

The minds behind the course

Fabio Cerullo

Senior Official ISC2 Authorised Instructor for CISSP, CCSP, CSSLP and SSCP

Fabio Cerullo, CISSP, CCSP, CSSLP, SSCP, is the Managing Director of Cycubix Ltd., where he leads cybersecurity consulting, compliance programs and professional training services for organisations across a wide range of industries. His work spans secure engineering, cloud security and guidance on major regulatory and certification requirements including ISO 27001, SOC2, FedRAMP, NIS2, PCI and GDPR.

He also serves as an ISC2 Senior Authorised Instructor, delivering advanced courses that help security and engineering teams build practical skills in cloud security, software security and information risk management. His cloud expertise is reinforced by his AWS Certified Solutions Architect and AWS Security Specialty certifications and hands-on experience advising organisations on secure architecture and cloud-native security practices.

He is an active contributor to the OWASP Foundation, regularly providing training, speaking at industry events and supporting community initiatives focused on modern application security. He volunteers as Google Summer of Code administrator, mentoring new students into the cybersecurity field and guiding them through their first contributions to open source security projects.

Originally from Argentina and now based in Ireland, he holds a master’s degree in computer engineering. His interests include emerging technologies, with a particular focus on AI risks and secure AI engineering. Outside of his professional work he enjoys spending time with his family, running outdoors, and actively supporting initiatives that aim to make high-quality cyber-security education accessible to a broader audience.

Show (Instructors)

The minds behind the course

The minds behind the course

Fabio Cerullo

Fabio Cerullo, CISSP, CCSP, CSSLP, SSCP, is the Managing Director of Cycubix Ltd., where he leads cybersecurity consulting, compliance programs and professional training services for organisations across a wide range of industries. His work spans secure engineering, cloud security and guidance on major regulatory and certification requirements including ISO 27001, SOC2, FedRAMP, NIS2, PCI and GDPR.

He also serves as an ISC2 Senior Authorised Instructor, delivering advanced courses that help security and engineering teams build practical skills in cloud security, software security and information risk management. His cloud expertise is reinforced by his AWS Certified Solutions Architect and AWS Security Specialty certifications and hands-on experience advising organisations on secure architecture and cloud-native security practices.

He is an active contributor to the OWASP Foundation, regularly providing training, speaking at industry events and supporting community initiatives focused on modern application security. He volunteers as Google Summer of Code administrator, mentoring new students into the cybersecurity field and guiding them through their first contributions to open source security projects.

Originally from Argentina and now based in Ireland, he holds a master’s degree in computer engineering. His interests include emerging technologies, with a particular focus on AI risks and secure AI engineering. Outside of his professional work he enjoys spending time with his family, running outdoors, and actively supporting initiatives that aim to make high-quality cyber-security education accessible to a broader audience.