PCI DSS v4.0.1
The Payment Card Industry Data Security Standard sets technical and operational requirements for any organization that stores, processes, or transmits payment card account data, or that can affect the security of the cardholder data environment, including service providers. Version 4.0.1 is organized into 12 principal requirements and is validated through a self-assessment questionnaire or a Qualified Security Assessor's Report on Compliance, as the payment brands and acquirers require.
Where we stand
132 of 205 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 1.1 NSC processes and roles | |||||
| 1.1.1 | Network security policies and procedures Controls: BIZ-14, CLOUD-03 | Passing | Not current | Not approved | Not yet |
| 1.1.2 | Network security roles and responsibilities Controls: BIZ-15, CLOUD-03 | Passing | Not current | Not approved | Not yet |
| 1.2 NSC configuration and maintenance | |||||
| 1.2.1 | NSC configuration standards Controls: CLOUD-02, CLOUD-03 | Passing | Not current | Approved | (29 d ago) |
| 1.2.2 | Change control for network connections and NSCs Controls: CLOUD-02, PDP-02 | Passing | Not current | Not approved | (23 d ago) |
| 1.2.3 | Network diagram | Unmapped | Unmapped | Unmapped | Not yet |
| 1.2.4 | Data-flow diagram | Unmapped | Unmapped | Unmapped | Not yet |
| 1.2.5 | Approved services, protocols, and ports Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 1.2.6 | Insecure services secured Controls: CLOUD-03, CLOUD-04 | Passing | Not current | Approved | Not yet |
| 1.2.7 | Semiannual NSC configuration review | Unmapped | Unmapped | Unmapped | Not yet |
| 1.2.8 | NSC configuration files secured Controls: CLOUD-02, PDP-06 | Passing | Current | Approved | (29 d ago) |
| 1.3 CDE network access restrictions | |||||
| 1.3.1 | Inbound CDE traffic restricted Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 1.3.2 | Outbound CDE traffic restricted | Unmapped | Unmapped | Unmapped | Not yet |
| 1.3.3 | Wireless networks separated from the CDE | Unmapped | Unmapped | Unmapped | Not yet |
| 1.4 Trusted and untrusted network connections | |||||
| 1.4.1 | NSCs between trusted and untrusted networks Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 1.4.2 | Inbound untrusted traffic restricted Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 1.4.3 | Anti-spoofing | Unmapped | Unmapped | Unmapped | Not yet |
| 1.4.4 | No direct untrusted access to stored CHD | Unmapped | Unmapped | Unmapped | Not yet |
| 1.4.5 | Internal addressing disclosure limited | Unmapped | Unmapped | Unmapped | Not yet |
| 1.5 Devices connected to both untrusted networks and the CDE | |||||
| 1.5.1 | Security controls on dual-connected devices | Unmapped | Unmapped | Unmapped | Not yet |
| 2.1 Configuration processes and roles | |||||
| 2.1.1 | Secure configuration policies and procedures Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 2.1.2 | Secure configuration roles and responsibilities Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| 2.2 Secure system configuration | |||||
| 2.2.1 | Configuration standards Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| 2.2.2 | Vendor default accounts | Unmapped | Unmapped | Unmapped | Not yet |
| 2.2.3 | Primary functions by security level Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| 2.2.4 | Only necessary functionality enabled Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| 2.2.5 | Insecure services justified | Unmapped | Unmapped | Unmapped | Not yet |
| 2.2.6 | Security parameters prevent misuse | Unmapped | Unmapped | Unmapped | Not yet |
| 2.2.7 | Non-console administrative access encrypted Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| 2.3 Wireless environment configuration | |||||
| 2.3.1 | Wireless vendor defaults changed | Unmapped | Unmapped | Unmapped | Not yet |
| 2.3.2 | Wireless encryption key changes | Unmapped | Unmapped | Unmapped | Not yet |
| 3.1 Stored data protection processes and roles | |||||
| 3.1.1 | Stored account data policies and procedures Controls: BIZ-14, DATA-04 | Passing | Not current | Not approved | Not yet |
| 3.1.2 | Stored account data roles and responsibilities Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| 3.2 Account data storage minimization | |||||
| 3.2.1 | Data retention and disposal Controls: DATA-04, DATA-05 | Passing | Not current | Not approved | Not yet |
| 3.3 Sensitive authentication data after authorization | |||||
| 3.3.1 | SAD not retained after authorization | Unmapped | Unmapped | Unmapped | Not yet |
| 3.3.2 | Pre-authorization SAD encrypted | Unmapped | Unmapped | Unmapped | Not yet |
| 3.3.3 | Issuer SAD storage | Unmapped | Unmapped | Unmapped | Not yet |
| 3.4 PAN display and copy restrictions | |||||
| 3.4.1 | PAN masking | Unmapped | Unmapped | Unmapped | Not yet |
| 3.4.2 | PAN copy through remote access prevented | Unmapped | Unmapped | Unmapped | Not yet |
| 3.5 PAN secured in storage | |||||
| 3.5.1 | PAN rendered unreadable Controls: DATA-02 | Passing | Not current | Not approved | Not yet |
| 3.6 Protection of cryptographic keys | |||||
| 3.6.1 | Key protection procedures Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| 3.7 Key lifecycle management | |||||
| 3.7.1 | Strong key generation Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| 3.7.2 | Secure key distribution | Unmapped | Unmapped | Unmapped | Not yet |
| 3.7.3 | Secure key storage | Unmapped | Unmapped | Unmapped | Not yet |
| 3.7.4 | Key changes at end of cryptoperiod | Unmapped | Unmapped | Unmapped | Not yet |
| 3.7.5 | Key retirement and replacement Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| 3.7.6 | Split knowledge and dual control | Unmapped | Unmapped | Unmapped | Not yet |
| 3.7.7 | Unauthorized key substitution prevented | Unmapped | Unmapped | Unmapped | Not yet |
| 3.7.8 | Key custodian acknowledgment Controls: PEOPLE-04 | Passing | Current | Approved | (4 mo ago) |
| 3.7.9 | Customer key guidance (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 4.1 Transmission protection processes and roles | |||||
| 4.1.1 | Transmission security policies and procedures Controls: BIZ-14, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| 4.1.2 | Transmission security roles and responsibilities Controls: BIZ-15, DATA-03 | Passing | Not current | Not approved | (8 h ago) |
| 4.2 PAN protection during transmission | |||||
| 4.2.1 | Strong cryptography for PAN in transit Controls: CLOUD-01, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| 4.2.2 | PAN in end-user messaging Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| 5.1 Anti-malware processes and roles | |||||
| 5.1.1 | Anti-malware policies and procedures Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 5.1.2 | Anti-malware roles and responsibilities Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| 5.2 Malware prevention and detection | |||||
| 5.2.1 | Anti-malware deployed | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.2 | Malware detection and removal | Unmapped | Unmapped | Unmapped | Not yet |
| 5.2.3 | Evaluation of systems not at risk Controls: CLOUD-04 | Passing | Not current | Approved | Not yet |
| 5.3 Anti-malware operation and monitoring | |||||
| 5.3.1 | Automatic anti-malware updates | Unmapped | Unmapped | Unmapped | Not yet |
| 5.3.2 | Scanning or behavioral analysis | Unmapped | Unmapped | Unmapped | Not yet |
| 5.3.3 | Removable media scanning | Unmapped | Unmapped | Unmapped | Not yet |
| 5.3.4 | Anti-malware audit logs Controls: MON-01 | Not passing | Not current | Not approved | (3 mo ago) |
| 5.3.5 | Anti-malware cannot be disabled | Unmapped | Unmapped | Unmapped | Not yet |
| 5.4 Anti-phishing | |||||
| 5.4.1 | Phishing detection and protection | Unmapped | Unmapped | Unmapped | Not yet |
| 6.1 Secure development processes and roles | |||||
| 6.1.1 | Secure development policies and procedures Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 6.1.2 | Secure development roles and responsibilities Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| 6.2 Secure software development | |||||
| 6.2.1 | Secure development of bespoke software Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| 6.2.2 | Annual developer security training Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| 6.2.3 | Pre-release code review Controls: APP-02, PDP-03 | Not passing | Not current | Not approved | (8 h ago) |
| 6.2.4 | Prevention of common software attacks Controls: APP-01, APP-02 | Not passing | Not current | Approved | (3 mo ago) |
| 6.3 Vulnerability identification and remediation | |||||
| 6.3.1 | Vulnerability identification and risk ranking Controls: MON-05, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| 6.3.2 | Software component inventory | Unmapped | Unmapped | Unmapped | Not yet |
| 6.3.3 | Security patching timelines Controls: CLOUD-05, IT-03, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| 6.4 Public-facing web application protection | |||||
| 6.4.1 | Web application assessment or protection | Unmapped | Unmapped | Unmapped | Not yet |
| 6.4.2 | Automated web attack prevention | Unmapped | Unmapped | Unmapped | Not yet |
| 6.4.3 | Payment page script management | Unmapped | Unmapped | Unmapped | Not yet |
| 6.5 Secure change management | |||||
| 6.5.1 | Change control procedures Controls: PDP-02, PDP-03, PDP-14 | Not passing | Not current | Not approved | (8 h ago) |
| 6.5.2 | Post-change PCI DSS confirmation Controls: PDP-14 | Passing | Current | Approved | (4 mo ago) |
| 6.5.3 | Pre-production separated from production Controls: CLOUD-06 | Passing | Current | Approved | (29 d ago) |
| 6.5.4 | Separation of duties for deployment Controls: PDP-05 | Passing | Current | Not approved | (29 d ago) |
| 6.5.5 | No live PAN in pre-production | Unmapped | Unmapped | Unmapped | Not yet |
| 6.5.6 | Test data removed before production Controls: CLOUD-06 | Passing | Current | Approved | (29 d ago) |
| 7.1 Access restriction processes and roles | |||||
| 7.1.1 | Access restriction policies and procedures Controls: BIZ-14, IAM-04 | Passing | Not current | Not approved | (29 d ago) |
| 7.1.2 | Access restriction roles and responsibilities Controls: BIZ-15, IAM-04 | Passing | Not current | Not approved | (29 d ago) |
| 7.2 Access definition and assignment | |||||
| 7.2.1 | Access control model Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 7.2.2 | Least-privilege assignment Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 7.2.3 | Privilege approval Controls: IAM-07 | Not passing | Current | Not approved | (29 d ago) |
| 7.2.4 | Semiannual user access review Controls: IAM-09 | Passing | Current | Not approved | (29 d ago) |
| 7.2.5 | Application and system account privileges Controls: IAM-04 | Passing | Not current | Not approved | (29 d ago) |
| 7.2.6 | Query access to stored cardholder data | Unmapped | Unmapped | Unmapped | Not yet |
| 7.3 Access control systems | |||||
| 7.3.1 | Need-to-know access control system Controls: IAM-01, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 7.3.2 | Permissions enforced by job function Controls: IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 7.3.3 | Deny all by default Controls: IAM-04, IAM-05 | Passing | Not current | Not approved | (29 d ago) |
| 8.1 Identification and authentication processes and roles | |||||
| 8.1.1 | Identification and authentication policies and procedures Controls: BIZ-14, IAM-01 | Passing | Not current | Not approved | (29 d ago) |
| 8.1.2 | Identification and authentication roles and responsibilities Controls: BIZ-15, IAM-01 | Passing | Not current | Not approved | (29 d ago) |
| 8.2 User identification and account lifecycle | |||||
| 8.2.1 | Unique user IDs | Unmapped | Unmapped | Unmapped | Not yet |
| 8.2.2 | Shared and generic IDs restricted Controls: IAM-03 | Passing | Current | Not approved | (29 d ago) |
| 8.2.3 | Unique factors per customer (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 8.2.4 | Authorized identity lifecycle changes Controls: IAM-07 | Not passing | Current | Not approved | (29 d ago) |
| 8.2.5 | Immediate revocation on termination Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| 8.2.6 | Inactive accounts disabled within 90 days Controls: IAM-09 | Passing | Current | Not approved | (29 d ago) |
| 8.2.7 | Third-party remote access accounts | Unmapped | Unmapped | Unmapped | Not yet |
| 8.2.8 | 15-minute idle session timeout | Unmapped | Unmapped | Unmapped | Not yet |
| 8.3 Strong authentication | |||||
| 8.3.1 | Authentication factor required Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 8.3.2 | Authentication factors encrypted Controls: DATA-03, IAM-01 | Passing | Current | Not approved | (8 h ago) |
| 8.3.3 | Identity verified before factor changes | Unmapped | Unmapped | Unmapped | Not yet |
| 8.3.4 | Account lockout after failed attempts | Unmapped | Unmapped | Unmapped | Not yet |
| 8.3.5 | Unique initial and reset passwords Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| 8.3.6 | Password length and complexity Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| 8.3.7 | Password history of four Controls: IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| 8.3.8 | Authentication guidance for users Controls: IAM-03, PEOPLE-06 | Not passing | Current | Not approved | (8 h ago) |
| 8.3.9 | Single-factor password rotation Controls: IAM-02, IAM-08 | Not passing | Not current | Not approved | (8 h ago) |
| 8.3.10 | Customer password guidance (service providers) Controls: CUST-03 | Passing | Not current | Approved | Not yet |
| 8.3.11 | Tokens and certificates not shared | Unmapped | Unmapped | Unmapped | Not yet |
| 8.4 MFA into the CDE | |||||
| 8.4.1 | MFA for administrative CDE access Controls: IAM-02, IAM-06 | Not passing | Not current | Not approved | (8 h ago) |
| 8.4.2 | MFA for all CDE access Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 8.4.3 | MFA for remote network access Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 8.5 MFA system configuration | |||||
| 8.5.1 | MFA resistant to misuse Controls: IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| 8.6 Application and system account management | |||||
| 8.6.1 | Interactive use of system accounts | Unmapped | Unmapped | Unmapped | Not yet |
| 8.6.2 | No hard-coded passwords Controls: APP-01 | Passing | Current | Approved | (4 mo ago) |
| 8.6.3 | System account password protection Controls: IAM-03 | Passing | Current | Not approved | (29 d ago) |
| 9.1 Physical security processes and roles | |||||
| 9.1.1 | Physical security policies and procedures Controls: BIZ-14, PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.1.2 | Physical security roles and responsibilities Controls: BIZ-15, PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.2 Facility and system physical access controls | |||||
| 9.2.1 | Facility entry controls Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.2.2 | Publicly accessible network jacks restricted Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.2.3 | Network hardware access restricted Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.2.4 | Consoles locked when not in use Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.3 Personnel and visitor physical access | |||||
| 9.3.1 | Personnel physical access procedures Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.3.2 | Visitor access procedures Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.3.3 | Visitor badges surrendered Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.3.4 | Visitor log Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.4 Media with cardholder data | |||||
| 9.4.1 | Media physically secured Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.4.2 | Media classified by sensitivity Controls: DATA-01 | Passing | Not current | Not approved | Not yet |
| 9.4.3 | Media sent offsite secured | Unmapped | Unmapped | Unmapped | Not yet |
| 9.4.4 | Management approval for media movement | Unmapped | Unmapped | Unmapped | Not yet |
| 9.4.5 | Electronic media inventory logs Controls: IT-04 | Passing | Not current | Not approved | Not yet |
| 9.4.6 | Hard-copy destruction | Unmapped | Unmapped | Unmapped | Not yet |
| 9.4.7 | Electronic media destruction Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 9.5 POI device protection | |||||
| 9.5.1 | POI tampering and substitution protection | Unmapped | Unmapped | Unmapped | Not yet |
| 10.1 Logging processes and roles | |||||
| 10.1.1 | Logging and monitoring policies and procedures Controls: BIZ-14, MON-01 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.1.2 | Logging and monitoring roles and responsibilities Controls: BIZ-15, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.2 Audit log implementation | |||||
| 10.2.1 | Audit logging enabled Controls: MON-01, MON-02 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.2.2 | Audit log event details | Unmapped | Unmapped | Unmapped | Not yet |
| 10.3 Audit log protection | |||||
| 10.3.1 | Log read access restricted | Unmapped | Unmapped | Unmapped | Not yet |
| 10.3.2 | Logs protected from modification | Unmapped | Unmapped | Unmapped | Not yet |
| 10.3.3 | Central log backup Controls: MON-01 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.3.4 | Log integrity monitoring | Unmapped | Unmapped | Unmapped | Not yet |
| 10.4 Audit log review | |||||
| 10.4.1 | Daily review of critical logs Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.4.2 | Periodic review of other logs Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 10.4.3 | Log exceptions addressed Controls: BIZ-03, MON-03 | Not passing | Not current | Not approved | (8 h ago) |
| 10.5 Audit log retention | |||||
| 10.5.1 | 12-month log retention | Unmapped | Unmapped | Unmapped | Not yet |
| 10.6 Time synchronization | |||||
| 10.6.1 | Clock synchronization technology | Unmapped | Unmapped | Unmapped | Not yet |
| 10.6.2 | Correct and consistent time | Unmapped | Unmapped | Unmapped | Not yet |
| 10.6.3 | Time settings protected | Unmapped | Unmapped | Unmapped | Not yet |
| 10.7 Critical security control failures | |||||
| 10.7.1 | Control failure detection (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 10.7.2 | Control failure detection | Unmapped | Unmapped | Unmapped | Not yet |
| 10.7.3 | Control failure response Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| 11.1 Security testing processes and roles | |||||
| 11.1.1 | Security testing policies and procedures Controls: BIZ-14, MON-04, MON-05 | Not passing | Not current | Not approved | (8 h ago) |
| 11.1.2 | Security testing roles and responsibilities Controls: BIZ-15, MON-05 | Not passing | Not current | Not approved | (3 mo ago) |
| 11.2 Wireless access point management | |||||
| 11.2.1 | Wireless access point detection | Unmapped | Unmapped | Unmapped | Not yet |
| 11.2.2 | Authorized wireless access point inventory Controls: IT-04 | Passing | Not current | Not approved | Not yet |
| 11.3 Vulnerability scanning | |||||
| 11.3.1 | Quarterly internal vulnerability scans Controls: MON-05, MON-06 | Not passing | Not current | Not approved | (3 mo ago) |
| 11.3.2 | Quarterly ASV external scans | Unmapped | Unmapped | Unmapped | Not yet |
| 11.4 Penetration testing | |||||
| 11.4.1 | Penetration testing methodology Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| 11.4.2 | Internal penetration testing Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| 11.4.3 | External penetration testing Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| 11.4.4 | Penetration test findings corrected Controls: BIZ-09, MON-04, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| 11.4.5 | Segmentation control testing Controls: MON-04 | Not passing | Current | Not approved | (8 h ago) |
| 11.4.6 | Semiannual segmentation testing (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 11.4.7 | Customer penetration testing support (multi-tenant providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 11.5 Intrusion and change detection | |||||
| 11.5.1 | Intrusion detection and prevention | Unmapped | Unmapped | Unmapped | Not yet |
| 11.5.2 | Change detection on critical files | Unmapped | Unmapped | Unmapped | Not yet |
| 11.6 Payment page change detection | |||||
| 11.6.1 | Payment page tamper detection | Unmapped | Unmapped | Unmapped | Not yet |
| 12.1 Information security policy | |||||
| 12.1.1 | Information security policy established Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 12.1.2 | Annual policy review Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| 12.1.3 | Security roles defined and acknowledged Controls: BIZ-15, PEOPLE-04, PEOPLE-08 | Not passing | Not current | Not approved | (4 mo ago) |
| 12.1.4 | Executive responsibility for security Controls: BIZ-11, BIZ-12, BIZ-15 | Passing | Not current | Not approved | Not yet |
| 12.2 Acceptable use | |||||
| 12.2.1 | Acceptable use policies Controls: IT-01 | Passing | Not current | Approved | Not yet |
| 12.3 Risk identification and management | |||||
| 12.3.1 | Targeted risk analysis Controls: BIZ-04, BIZ-05 | Passing | Not current | Not approved | (4 mo ago) |
| 12.3.2 | Customized approach risk analysis | Unmapped | Unmapped | Unmapped | Not yet |
| 12.3.3 | Cipher suite and protocol review Controls: DATA-06 | Not passing | Not current | Not approved | Not yet |
| 12.3.4 | Hardware and software technology review | Unmapped | Unmapped | Unmapped | Not yet |
| 12.4 PCI DSS compliance management | |||||
| 12.4.1 | Executive compliance accountability (service providers) Controls: BIZ-11, BIZ-12, BIZ-15 | Passing | Not current | Not approved | Not yet |
| 12.4.2 | Quarterly operational reviews (service providers) Controls: BIZ-08 | Passing | Not current | Approved | Not yet |
| 12.5 Scope documentation and validation | |||||
| 12.5.1 | In-scope system inventory Controls: IT-04, IT-05 | Passing | Not current | Not approved | Not yet |
| 12.5.2 | Annual scope confirmation | Unmapped | Unmapped | Unmapped | Not yet |
| 12.5.3 | Organizational change scope review (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 12.6 Security awareness | |||||
| 12.6.1 | Security awareness program Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 12.6.2 | Annual awareness program review Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 12.6.3 | Awareness training and policy acknowledgment Controls: PEOPLE-04, PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 12.7 Personnel screening | |||||
| 12.7.1 | Pre-hire screening Controls: PEOPLE-01 | Not passing | Current | Not approved | (4 mo ago) |
| 12.8 Third-party service provider risk | |||||
| 12.8.1 | TPSP list Controls: VEND-01 | Passing | Not current | Not approved | Not yet |
| 12.8.2 | TPSP written agreements Controls: VEND-02 | Passing | Not current | Not approved | Not yet |
| 12.8.3 | TPSP due diligence Controls: VEND-03 | Passing | Not current | Not approved | Not yet |
| 12.8.4 | Annual TPSP compliance monitoring Controls: VEND-04 | Not passing | Current | Not approved | (8 h ago) |
| 12.8.5 | TPSP responsibility matrix | Unmapped | Unmapped | Unmapped | Not yet |
| 12.9 TPSP support for customer compliance | |||||
| 12.9.1 | Written responsibility acknowledgment (service providers) Controls: CUST-02 | Passing | Not current | Approved | Not yet |
| 12.9.2 | Compliance information for customers (service providers) | Unmapped | Unmapped | Unmapped | Not yet |
| 12.10 Incident response | |||||
| 12.10.1 | Incident response plan Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| 12.10.2 | Annual plan review and test Controls: BIZ-02, BIZ-21 | Passing | Not current | Not approved | (3 mo ago) |
| 12.10.3 | 24/7 incident response personnel Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
| 12.10.4 | Incident response training Controls: BIZ-21 | Passing | Current | Approved | (4 mo ago) |
| 12.10.5 | Security alert monitoring in the plan Controls: BIZ-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 12.10.6 | Plan updated with lessons learned Controls: BIZ-02, BIZ-09 | Passing | Not current | Not approved | (3 mo ago) |
| 12.10.7 | Response to unexpected stored PAN Controls: BIZ-02 | Passing | Not current | Not approved | (3 mo ago) |
