{"id":3772,"date":"2015-12-01T23:29:35","date_gmt":"2015-12-01T23:29:35","guid":{"rendered":"https:\/\/www.process.st\/templates\/pci-compliance-checklist\/"},"modified":"2024-02-28T16:09:00","modified_gmt":"2024-02-28T16:09:00","slug":"pci-compliance-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/pci-compliance-checklist\/","title":{"rendered":"PCI Compliance Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/lOESpZteDd2S1SgprDVBwg.png\" alt=\"Introduction\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/lOESpZteDd2S1SgprDVBwg.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>In this modern day and age it is more important than ever that all sensitive information is properly secure and protected. To that end, this checklist will take you through the steps to ensuring your complete compliance with Payment Card Industry Data Security Standards (PCI DSS).<\/p>\n<p>Although the official PCI DSS requires an annual review and submission of proof, it is recommended that you run this checklist at least quarterly (or after any changes in your system relating to cardholder data) to keep up to date on security.<\/p>\n<p>Follow this PCI compliance checklist to ensure complete compliance and avoid any legal trouble.<\/p>\n<p>Continue to tackle the first part of the process:&nbsp;<strong><\/strong>Assessing.<\/p>\n<p>(Source: <a href=\"https:\/\/www.pcisecuritystandards.org\/merchants\/how_to_be_compliant.php\" rel=\"nofollow noopener\" target=\"_blank\">pcisecuritystandards.org<\/a>)<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"assess\">\n<h2>Assess:<\/h2>\n<\/section>\n<section id=\"determine-merchant-level\">\n<h2>Determine merchant level<\/h2>\n<div class=\"text-content\">\n<p>According to <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/PCI-assessment\" rel=\"nofollow noopener\" target=\"_blank\">Search Security<\/a>, level 1 merchants must have their compliance assessed by a Qualified Security Assessor (QSA). The PCI Security Standards Council (PSISSC) has compiled a list of companies that can do it for you, available <a href=\"https:\/\/www.pcisecuritystandards.org\/approved_companies_providers\/qsa_companies.php\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p>While this is necessary for level 1 merchants, merchants at levels 2-4 can also call in the help of a QSA if they want to avoid extra work.<\/p>\n<p>(Source: <a href=\"https:\/\/www.pcicomplianceguide.org\/pci-faqs-2\/#5\" target=\"_blank\" rel=\"nofollow noopener\">pcicomplianceguide.org<\/a>)<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/k2JVVnd2Mttj_JwkBTdK5Q.png\" alt=\"The merchant levels as defined by Visa.\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/k2JVVnd2Mttj_JwkBTdK5Q.png\" \/> <\/a><figcaption>\n    The merchant levels as defined by Visa.<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<\/section>\n<section id=\"decide-if-you-need-to-comply\">\n<h2>Decide if you need to comply<\/h2>\n<div class=\"text-content\">\n<p>According to <a href=\"https:\/\/www.braintreepayments.com\/blog\/who-needs-to-be-pci-compliant\/\" rel=\"nofollow noopener\" target=\"_blank\">Braintree<\/a>, &quot;any business that processes, handles or stores credit card data on behalf of a merchant is required to be&nbsp;PCI&nbsp;DSS&nbsp;Compliant.&quot;<\/p>\n<p><a href=\"https:\/\/www.pcicomplianceguide.org\/pci-faqs-2\/#2\" rel=\"nofollow noopener\" target=\"_blank\">Compliance Guide<\/a> adds:<\/p>\n<p>&quot;PCI applies to ALL organizations or merchants, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data. Said another way,<strong> if any customer of that organization ever pays the merchant directly using a credit card or debit card, then the PCI DSS requirements apply<\/strong>.&quot;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"work-out-the-kind-of-assessment-you-should-do\">\n<h2>Work out the kind of assessment you should do<\/h2>\n<div class=\"text-content\">\n<p>How to determine your assessment level, along with&nbsp;the latest assessment forms, can be found in the document below:<\/p>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>There are <strong>nine&nbsp;kinds<\/strong> of Self-Assessment Questionnaire (<strong>SAQ<\/strong>). The kind that applies to you dictates the level of compliance you need to meet. This table will tell you which SAQ classification you are:<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/rZeB3TBYhDNXu7qUbHNFSQ.png\" alt=\"Work out the kind of assessment you should do\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/rZeB3TBYhDNXu7qUbHNFSQ.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p><strong>When you move onto the next section, select the task appropriate to your SAQ level.<\/strong><\/p>\n<p>While the <strong>Remediate section<\/strong> of PCI Compliance <strong>contains general steps applicable to all merchants<\/strong>, the different SAQ levels might need you to have extra security measures in place.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq\">\n<h2>SAQ:<\/h2>\n<\/section>\n<section id=\"saq-a\">\n<h2>SAQ A<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ A, as laid out in the previous task, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-aep\">\n<h2>SAQ A-EP<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ A-EP, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-b\">\n<h2>SAQ B<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ B, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-bip\">\n<h2>SAQ B-IP<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ B-IP, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-cvt\">\n<h2>SAQ C-VT<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ C-VT, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-c\">\n<h2>SAQ C<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ C, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-dmerchant\">\n<h2>SAQ D-Merchant<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ D-Merchant, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"saq-dservice-provider\">\n<h2>SAQ D-Service Provider<\/h2>\n<div class=\"text-content\">\n<p>If you meet the requirements for SAQ D-Service Provider, as laid out in task 4, this is the compliance form you must fill in.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"remediate\">\n<h2>Remediate:<\/h2>\n<div class=\"text-content\">\n<p>Depending on the results of your self-assessment, you may have to carry out some or all of the below tasks before you are fully compliant with PCI requirements.<\/p>\n<p>If you are a level 1 merchant, you must use a certified QSA company and cannot carry out the steps yourself. A list of certified QSA firms can be found <a href=\"https:\/\/www.pcisecuritystandards.org\/approved_companies_providers\/approved_scanning_vendors.php\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p>If you prefer you can call in a QSA firm regardless of your merchant level, but know you don't have to.<\/p>\n<p><strong>For each of the following tasks you must write and maintain documentation that explains the steps taken to comply. The documentation must be available to all relevant staff.<\/strong><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"account-for-card-brand-variance\">\n<h2>Account for card brand variance<\/h2>\n<div class=\"text-content\">\n<p><strong>Depending on the card brand<\/strong> you use, <strong>compliance procedures<\/strong> will be slightly different. See the links below for different company's policies on data security.<\/p>\n<ul>\n<li>American Express:&nbsp;<a href=\"http:\/\/www.americanexpress.com\/datasecurity\" rel=\"nofollow noopener\" target=\"_blank\">www.americanexpress.com\/datasecurity<\/a><\/li>\n<li>Discover Financial Services:&nbsp;<a href=\"http:\/\/www.discovernetwork.com\/merchants\/fraud-protection\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/www.discovernetwork.com\/merchants\/fraud-protection<\/a><\/li>\n<li>JCB International:&nbsp;<a href=\"http:\/\/partner.jcbcard.com\/security\/jcbprogram\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/partner.jcbcard.com\/security\/jcbprogram\/index.html<\/a><\/li>\n<li>MasterCard:&nbsp;<a href=\"http:\/\/www.mastercard.com\/sdp\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/www.mastercard.com\/sdp<\/a><\/li>\n<li>Visa Inc:&nbsp;<a href=\"http:\/\/www.visa.com\/cisp\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/www.visa.com\/cisp<\/a><\/li>\n<li>Visa Europe:&nbsp;<a href=\"http:\/\/www.visaeurope.com\/ais\" rel=\"nofollow noopener\" target=\"_blank\">http:\/\/www.visaeurope.com\/ais<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"maintain-a-firewall-configuration\">\n<h2>Maintain a firewall configuration<\/h2>\n<div class=\"text-content\">\n<p><strong>Firewalls<\/strong> are devices that control computer traffic allowed in and out of an organization\u2019s network, along with sensitive areas in&nbsp;its internal network. Firewalls&nbsp;can also appear in other system components.<\/p>\n<p><strong>All your networking devices that transmit or receive cardholder details should be tested<\/strong>. The steps to do so are as follows.<\/p>\n<p><strong>1.<\/strong>&nbsp; &nbsp;<strong>Establish and implement firewall and router configuration standards<\/strong> that:<\/p>\n<ul>\n<li>Formalize testing whenever configurations change<\/li>\n<li>Identify all connections between the cardholder data environment and other networks (including wireless) with documentation and diagrams<\/li>\n<li>Document business justification and various technical settings for each implementation<\/li>\n<li>Diagram all cardholder data flows across systems and networks<\/li>\n<li>Stipulate a review of configuration rule sets at least every six months<\/li>\n<\/ul>\n<p><strong>2.<\/strong>&nbsp; &nbsp;<strong>Build firewall and router configurations that restrict all traffic<\/strong>, inbound and outbound, from \u201cuntrusted\u201d networks (including wireless) and hosts, and specifically deny all other traffic except for protocols necessary for the cardholder data environment.<\/p>\n<p><strong>3. &nbsp;&nbsp;Prohibit direct public access<\/strong> between the Internet and any system component in the cardholder data environment.<\/p>\n<p><strong>4.<\/strong> &nbsp;&nbsp;<strong>Install <a href=\"http:\/\/www.firewallguide.com\/software.htm\" rel=\"nofollow noopener\" target=\"_blank\">personal firewall software<\/a><\/strong> on any mobile and\/or employee-owned devices that connect to the Internet when outside the network, and which are also used to access the network.<\/p>\n<p>An approved method for installing PCI-compliant firewalls is available below.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"eliminate-the-use-of-default-credentials\">\n<h2>Eliminate the use of default credentials<\/h2>\n<div class=\"text-content\">\n<p>The <strong>first thing a hacker would use <\/strong>when trying to get into your&nbsp;system<strong> is known default credentials<\/strong>. These include:<\/p>\n<ul>\n<li>[none]<\/li>\n<li>[name of product \/ vendor]<\/li>\n<li>1234 or 4321<\/li>\n<li>access<\/li>\n<li>admin<\/li>\n<li>anonymous<\/li>\n<li>database<\/li>\n<li>guest<\/li>\n<li>manager<\/li>\n<li>pass<\/li>\n<li>password<\/li>\n<li>root<\/li>\n<li>sa<\/li>\n<li>secret<\/li>\n<li>sysadmin<\/li>\n<li>user<\/li>\n<\/ul>\n<p>To ensure you don't overlook this, <strong>follow the guidelines below<\/strong>:<\/p>\n<ul>\n<li>Immediately <a href=\"https:\/\/strongpasswordgenerator.com\/\" rel=\"nofollow noopener\" target=\"_blank\">change all credentials<\/a> for every&nbsp;account and disable any default accounts (such as 'admin')<\/li>\n<li>Keep a list of all systems that can be accessed using login credentials<\/li>\n<li>Keep system configurations updated in line with new vulnerabilities<\/li>\n<li>Encrypt all non-console admin access points (such as browser-based management tools)<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"protect-stored-cardholder-data\">\n<h2>Protect stored cardholder data<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/sTpY0q7ThsedNNC9QSJEvQ.png\" alt=\"Protect stored cardholder data\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/sTpY0q7ThsedNNC9QSJEvQ.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>To account for as many vulnerabilities as possible, <strong>don't store any more cardholder data than is absolutely necessary<\/strong>.<\/p>\n<ul>\n<li><strong>Review the necessity <\/strong>to keep data (at least quarterly) and <strong>purge<\/strong> anything you don't need for legal\/compliance\/business reasons.<\/li>\n<li><strong>Never store authentication data<\/strong>. It should be purged directly after authentication (PIN codes for example).<\/li>\n<li>Ensure Primary Account Number (<strong>PAN<\/strong>) <strong>is unreadable<\/strong> anywhere it is stored. For this you can use one-way hash functions, truncation, index tokens or strong cryptography.&nbsp;<\/li>\n<li><strong>Protect encryption keys<\/strong>.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"encrypt-transmission-of-cardholder-data\">\n<h2>Encrypt transmission of cardholder data<\/h2>\n<div class=\"text-content\">\n<p>When <strong>transmitting cardholder data<\/strong> over open public networks (internet, satellite, wireless networks, cellular networks), you need to&nbsp;to <strong>employ strong cryptography<\/strong> such as TLS, SSH or IPSec.&nbsp;<\/p>\n<p>As added security measures, remember to:<\/p>\n<ul>\n<li><strong>Never send unprotected<\/strong> <strong>PANs<\/strong> via SMS, email or instant message.<\/li>\n<li><strong>Document all security procedures<\/strong> regarding the above and make them available to only the&nbsp;relevant people.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"protect-systems-against-viruses-and-malware\">\n<h2>Protect systems against viruses and malware<\/h2>\n<div class=\"text-content\">\n<p>On&nbsp;systems generally affected by viruses and malware (PCs and servers) you need to<strong>&nbsp;install or update <a href=\"https:\/\/www.avast.com\/en-eu\/avast-for-business\" rel=\"nofollow noopener\" target=\"_blank\">anti-virus software<\/a><\/strong> that has the ability to <strong>scan and generate logs<\/strong>. The <strong>logs must then be retained<\/strong> as part of the PCI compliance process.<\/p>\n<p>Remember to:<\/p>\n<ul>\n<li>Ensure the anti-virus can't be disabled without review on a case-by-case basis<\/li>\n<li>Check that any systems not commonly effected by viruses (usually all but Microsoft Windows) still don't need anti-virus.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"update-security\">\n<h2>Update security<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/kQeE94SbZqW69LU-Q2tM-A.png\" alt=\"Update security\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/kQeE94SbZqW69LU-Q2tM-A.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>As new methods to compromise security are developed, the creators of <strong>security software<\/strong> release <strong>patches<\/strong> to protect systems against new threats. This is only the only way to update your security however, and you must run&nbsp;the following guidelines in full:<\/p>\n<ul>\n<li><strong>Use a <\/strong><a href=\"https:\/\/www.owasp.org\/index.php\/OWASP_Risk_Rating_Methodology\" rel=\"nofollow noopener\" target=\"_blank\"><strong>methodology<\/strong> to identify vulnerabilities and apply risk rankings<\/a>.<br \/> &nbsp;<\/li>\n<li>Ensure all <strong>patches are up to date<\/strong> for all software, installing them within one month of release.\n<\/li>\n<li><strong>Develop internal and external software applications<\/strong> (including web-based administrative access to applications) in accordance with PCI DSS and based on industry best practices. Incorporate information security throughout the software development life cycle. This applies to all software developed internally as well as bespoke or custom software developed by a third party.<br \/> &nbsp;<\/li>\n<li><strong>Follow change control processes<\/strong> and procedures for all changes to system components.<br \/> &nbsp;<\/li>\n<li><strong>Prevent common coding vulnerabilities<\/strong> in software development processes by training developers in secure coding techniques and developing applications based on secure coding guidelines \u2013 including how sensitive data is handled in memory.<br \/> &nbsp;<\/li>\n<li>Ensure all public-facing web apps are protected against known attacks by performing <strong>application vulnerability assessments<\/strong> at least annually or&nbsp;after any changes. Alternatively you can install an automated technical solution that detects and prevents web-based attacks (for example, a web-app firewall) to continually check all traffic.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"limit-the-spread-of-cardholder-details\">\n<h2>Limit the spread of cardholder details<\/h2>\n<div class=\"text-content\">\n<p>To further minimize the risk of vulnerabilities&nbsp;you need to&nbsp;<strong>keep cardholder detail access on as few systems as possible<\/strong>. One of the best ways to do this is to <strong>limit the access<\/strong> to staff whose job directly&nbsp;requires&nbsp;the information.<\/p>\n<p><strong>Set a default 'deny all' security on access and only allow specific staff through<\/strong>.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"authenticate-user-access\">\n<h2>Authenticate user access<\/h2>\n<div class=\"text-content\">\n<p><strong>Every user<\/strong> with access to the <strong>Cardholder Data Environment<\/strong> must have a <strong>unique ID<\/strong>. This allows a business to trace every action to a specific individual should something breach security. Coupled with the unique ID, ensure every user&nbsp;has&nbsp;a <strong>strong unique password<\/strong> for authentication.<\/p>\n<p>See <a href=\"https:\/\/strongpasswordgenerator.com\/\" rel=\"nofollow noopener\" target=\"_blank\">here <\/a>for guidelines and tools for creating strong passwords.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"restrict-physical-access-to-data\">\n<h2>Restrict physical access to data<\/h2>\n<div class=\"text-content\">\n<p>Don't overlook the possibility of <strong>physical theft<\/strong> of documents and hard disks. This is just as <strong>vital<\/strong> to the PCI Compliance process as safeguarding the digital side of the company, and needs to be addressed by:<\/p>\n<ul>\n<li><strong>Checking facility entry controls<\/strong>. Ensure the use of keycards and identity cards to prevent&nbsp;unauthorized entry.<\/li>\n<li>Strictly <strong>controlling the distribution of physical copies<\/strong> of backup discs, receipts and other financial documents. Only give these when absolutely necessary.<\/li>\n<li><strong>Destroy media<\/strong> (sensitive or not) <strong>when no longer needed<\/strong>.<\/li>\n<li><strong>Keep data storage areas tightly locked and secure<\/strong>.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"log-access-to-data-and-resources\">\n<h2>Log access to data and resources<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/jqjn9-VKjQ7W5MMIijJCLg.png\" alt=\"Log access to data and resources\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/jqjn9-VKjQ7W5MMIijJCLg.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>If your system is compromised it will be extremely difficult to find the cause&nbsp;without data logs. <strong>Your software should automatically produce logs<\/strong> for you to audit in case of a security breach. If it does not, acquire software which serves this function; widely available software such as <a href=\"https:\/\/www.avast.com\/index\" rel=\"nofollow noopener\" target=\"_blank\">Avast! Anti-Virus<\/a>&nbsp;automatically writes logs, you just need to check custom software for this feature.<\/p>\n<p>Remember to:<\/p>\n<ul>\n<li>Ensure all logs are <strong>read-only<\/strong>.<\/li>\n<li>Implement <strong>audit trails<\/strong> to link all access to individual users.<\/li>\n<li><strong>Keep <\/strong>logs for at least <strong>one year<\/strong>.<\/li>\n<li><strong>Securely store<\/strong> all logs.<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"test-security-systems-and-processes\">\n<h2>Test security systems and processes<\/h2>\n<div class=\"text-content\">\n<p>Whilst you should regularly <strong>test your security systems<\/strong>, a definitive test should always be carried out for the PCI Compliance process. This test should include aspects such as:<\/p>\n<ul>\n<li>Checking for wireless access points (on a quarterly basis).<\/li>\n<li>Running internal and external <a href=\"http:\/\/sectools.org\/tag\/vuln-scanners\/\" rel=\"nofollow noopener\" target=\"_blank\">vulnerability scans<\/a>&nbsp;(quarterly).<\/li>\n<li>Carrying out <a href=\"http:\/\/www.computerworld.com\/article\/2536045\/endpoint-security\/five-free-pen-testing-tools.html\" rel=\"nofollow noopener\" target=\"_blank\">penetration testing<\/a>&nbsp;(annually).<\/li>\n<li>Employing a <a href=\"http:\/\/www.sans.org\/security-resources\/idfaq\/network_based.php\" rel=\"nofollow noopener\" target=\"_blank\">network intrusion system<\/a>.<\/li>\n<li>The presence of a change detection mechanism to alert employees of unauthorized modifications.<\/li>\n<\/ul>\n<p>This test is marked according to the <strong>Common Vulnerability Scoring System (CVSS)<\/strong>, on which more information can be found <a href=\"https:\/\/nvd.nist.gov\/cvss.cfm\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>.<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ujiRLu1mqlgEtD__ZtxDMg.png\" alt=\"Test security systems and processes\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ujiRLu1mqlgEtD__ZtxDMg.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<\/section>\n<section id=\"maintain-information-security-policy\">\n<h2>Maintain information security policy<\/h2>\n<div class=\"text-content\">\n<p>The method of&nbsp;putting an <strong>information security policy<\/strong> into place is up to you, but it needs to be implemented and should fulfill the following criteria:<\/p>\n<ul>\n<li>Come under <strong>annual review<\/strong>.<\/li>\n<li>Include a <strong>risk assessment policy<\/strong>.<\/li>\n<li>Define<strong> security responsibilities<\/strong> of each staff member.<\/li>\n<li>Enact&nbsp;a <strong>formal security awareness program<\/strong> regarding cardholder information.<\/li>\n<li><strong>Screen potential new staff<\/strong> prior to hiring.<\/li>\n<li><strong>Manage&nbsp;<\/strong>the<strong> sharing <\/strong>of&nbsp;cardholder<strong> data<\/strong>.<\/li>\n<li>Define an<strong> incident response plan<\/strong>.&nbsp;<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"report\">\n<h2>Report:<\/h2>\n<\/section>\n<section id=\"use-the-pci-reporting-template\">\n<h2>Use the PCI Reporting Template<\/h2>\n<div class=\"text-content\">\n<p>If you choose to do a self-assessment you have to submit a report to the PCI Security Standards Council after addressing&nbsp;any remedial issues outlined above.&nbsp;<\/p>\n<p>The report is to be sent to the merchant's acquiring bank.&nbsp;<\/p>\n<p><strong>Download the template below:<\/strong><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<p><a href=\"https:\/\/www.pcisecuritystandards.org\/index.php\" target=\"_blank\" rel=\"nofollow noopener\">PCI Security Standards Council<\/a> - <a href=\"https:\/\/www.pcisecuritystandards.org\/merchants\/how_to_be_compliant.php\" target=\"_blank\" rel=\"nofollow noopener\">How to Be Compliant<\/a><\/p>\n<p><a href=\"https:\/\/twitter.com\/whatisdotcom\" target=\"_blank\" rel=\"nofollow noopener\">Margaret Rouse<\/a> - <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/PCI-assessment\" target=\"_blank\" rel=\"nofollow noopener\">PCI Assessment Definition<\/a><\/p>\n<p><a href=\"https:\/\/www.pcicomplianceguide.org\/\" target=\"_blank\" rel=\"nofollow noopener\">PCI Compliance Guide<\/a> - <a href=\"https:\/\/www.pcicomplianceguide.org\/pci-faqs-2\/#5\" target=\"_blank\" rel=\"nofollow noopener\">PCI FAQs<\/a><\/p>\n<p><a href=\"https:\/\/www.braintreepayments.com\/blog\/\" target=\"_blank\" rel=\"nofollow noopener\">Braintree<\/a> - <a href=\"https:\/\/www.braintreepayments.com\/blog\/who-needs-to-be-pci-compliant\/\" target=\"_blank\" rel=\"nofollow noopener\">Who Needs to be PCI Compliant?<\/a><\/p>\n<\/p><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction In this modern day and age it is more important than ever that all sensitive information is properly secure and protected. To that end, this checklist will take you through the steps to ensuring your complete compliance with Payment Card Industry Data Security Standards (PCI DSS). Although the official PCI DSS requires an annual [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":3773,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"31","template_description":"Run this checklist at least annually to ensure your compliance with PCI DSS","template_id":"utQCxZj_I8cGVaQ8mlhEzg","task_0":"Introduction","task_slug_0":"introduction","task_1":"Assess:","task_slug_1":"assess","task_2":"Determine merchant level","task_slug_2":"determine-merchant-level","task_3":"Decide if you need to comply","task_slug_3":"decide-if-you-need-to-comply","task_4":"Work out the kind of assessment you should do","task_slug_4":"work-out-the-kind-of-assessment-you-should-do","task_5":"SAQ:","task_slug_5":"saq","task_6":"SAQ A","task_slug_6":"saq-a","task_7":"SAQ A-EP","task_slug_7":"saq-aep","task_8":"SAQ B","task_slug_8":"saq-b","task_9":"SAQ B-IP","task_slug_9":"saq-bip","task_10":"SAQ C-VT","task_slug_10":"saq-cvt","task_11":"SAQ C","task_slug_11":"saq-c","task_12":"SAQ D-Merchant","task_slug_12":"saq-dmerchant","task_13":"SAQ D-Service Provider","task_slug_13":"saq-dservice-provider","task_14":"Remediate:","task_slug_14":"remediate","task_15":"Account for card brand variance","task_slug_15":"account-for-card-brand-variance","task_16":"Maintain a firewall configuration","task_slug_16":"maintain-a-firewall-configuration","task_17":"Eliminate the use of default credentials","task_slug_17":"eliminate-the-use-of-default-credentials","task_18":"Protect stored cardholder data","task_slug_18":"protect-stored-cardholder-data","task_19":"Encrypt transmission of cardholder data","task_slug_19":"encrypt-transmission-of-cardholder-data","task_20":"Protect systems against viruses and malware","task_slug_20":"protect-systems-against-viruses-and-malware","task_21":"Update security","task_slug_21":"update-security","task_22":"Limit the spread of cardholder details","task_slug_22":"limit-the-spread-of-cardholder-details","task_23":"Authenticate user access","task_slug_23":"authenticate-user-access","task_24":"Restrict physical access to data","task_slug_24":"restrict-physical-access-to-data","task_25":"Log access to data and resources","task_slug_25":"log-access-to-data-and-resources","task_26":"Test security systems and processes","task_slug_26":"test-security-systems-and-processes","task_27":"Maintain information security policy","task_slug_27":"maintain-information-security-policy","task_28":"Report:","task_slug_28":"report","task_29":"Use the PCI Reporting Template","task_slug_29":"use-the-pci-reporting-template","task_30":"Sources:","task_slug_30":"sources","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-3772","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-finance","category-miscellaneous"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/3772","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=3772"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/3772\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/3773"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=3772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=3772"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=3772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}