The most important thing for an organization is to pass the pci certification process
https://www.verygoodsecurity.com/blo...-days-with-vgs , after supports several new technologies and measures to help protect data from unauthorized access, use, disclosure, modification or destruction. These include encryption during transmission, multi-factor authentication, application whitelist, secure development lifecycle, and system monitoring. In addition, organizations must have systems in place to detect and respond to security incidents.