Templates
Information Security
PCI Compliance Checklist
🔒

PCI Compliance Checklist

1
Identify all cardholder data in your environment
2
Build a diagram indicating the flow of cardholder data
3
Conduct risk assessment
4
Eliminate the storage of sensitive cardholder data, if unnecessary
5
Implement measures to protect stored cardholder data
6
Investigate and utilize secure technologies to protect data transmitted across open, public networks
7
Create, maintain, and enforce a strong access control system
8
Ensure proper monitoring and testing of network resources
9
Develop and regularly review an information security policy
10
Ensure all systems and software are up to date
11
Establish a process to identify security vulnerabilities
12
Define and establish secure systems and application development practices
13
Regularly test security systems and processes
14
Approval: Risk Assessment Results
15
Assign a PCI DSS compliance officer
16
Define and establish an incident response plan
17
Train all staff on security awareness and procedures
18
Approval: Staff Training
19
Implement and regularly review audit logs
20
Ensure all access to network resources and cardholder data is on a need-to-know basis