This document discusses the Payment Card Industry Data Security Standard (PCI DSS) compliance requirements for organizations that handle credit card data. It outlines what types of data are considered sensitive, the costs of non-compliance, and principles for complying with PCI DSS requirements for securing credit card information stored in databases as well as unstructured data sources like spreadsheets and files. It recommends using software to automate the ongoing scanning, access management, and reviews needed to continually monitor and protect credit card information according to PCI DSS standards.