FintastIQTrust Center
LoginBook a Consultation
Framework

PCI DSS v4.0.1

Version: 4.0.1 (June 2024; future-dated requirements effective 2025-03-31)

The Payment Card Industry Data Security Standard sets technical and operational requirements for any organization that stores, processes, or transmits payment card account data, or that can affect the security of the cardholder data environment, including service providers. Version 4.0.1 is organized into 12 principal requirements and is validated through a self-assessment questionnaire or a Qualified Security Assessor's Report on Compliance, as the payment brands and acquirers require.

Official source

Summary

Where we stand

Controls
67%
Evidence
21%
Policies
20%

132 of 205 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
1.1 NSC processes and roles
1.1.1Network security policies and procedures
Controls: BIZ-14, CLOUD-03
PassingNot currentNot approvedNot yet
1.1.2Network security roles and responsibilities
Controls: BIZ-15, CLOUD-03
PassingNot currentNot approvedNot yet
1.2 NSC configuration and maintenance
1.2.1NSC configuration standards
Controls: CLOUD-02, CLOUD-03
PassingNot currentApproved(29 d ago)
1.2.2Change control for network connections and NSCs
Controls: CLOUD-02, PDP-02
PassingNot currentNot approved(23 d ago)
1.2.3Network diagramUnmappedUnmappedUnmappedNot yet
1.2.4Data-flow diagramUnmappedUnmappedUnmappedNot yet
1.2.5Approved services, protocols, and ports
Controls: CLOUD-03
PassingNot currentApprovedNot yet
1.2.6Insecure services secured
Controls: CLOUD-03, CLOUD-04
PassingNot currentApprovedNot yet
1.2.7Semiannual NSC configuration reviewUnmappedUnmappedUnmappedNot yet
1.2.8NSC configuration files secured
Controls: CLOUD-02, PDP-06
PassingCurrentApproved(29 d ago)
1.3 CDE network access restrictions
1.3.1Inbound CDE traffic restricted
Controls: CLOUD-03
PassingNot currentApprovedNot yet
1.3.2Outbound CDE traffic restrictedUnmappedUnmappedUnmappedNot yet
1.3.3Wireless networks separated from the CDEUnmappedUnmappedUnmappedNot yet
1.4 Trusted and untrusted network connections
1.4.1NSCs between trusted and untrusted networks
Controls: CLOUD-03
PassingNot currentApprovedNot yet
1.4.2Inbound untrusted traffic restricted
Controls: CLOUD-03
PassingNot currentApprovedNot yet
1.4.3Anti-spoofingUnmappedUnmappedUnmappedNot yet
1.4.4No direct untrusted access to stored CHDUnmappedUnmappedUnmappedNot yet
1.4.5Internal addressing disclosure limitedUnmappedUnmappedUnmappedNot yet
1.5 Devices connected to both untrusted networks and the CDE
1.5.1Security controls on dual-connected devicesUnmappedUnmappedUnmappedNot yet
2.1 Configuration processes and roles
2.1.1Secure configuration policies and procedures
Controls: BIZ-14
PassingNot currentNot approvedNot yet
2.1.2Secure configuration roles and responsibilities
Controls: BIZ-15
PassingNot currentNot approvedNot yet
2.2 Secure system configuration
2.2.1Configuration standards
Controls: CLOUD-04
PassingNot currentApprovedNot yet
2.2.2Vendor default accountsUnmappedUnmappedUnmappedNot yet
2.2.3Primary functions by security level
Controls: CLOUD-04
PassingNot currentApprovedNot yet
2.2.4Only necessary functionality enabled
Controls: CLOUD-04
PassingNot currentApprovedNot yet
2.2.5Insecure services justifiedUnmappedUnmappedUnmappedNot yet
2.2.6Security parameters prevent misuseUnmappedUnmappedUnmappedNot yet
2.2.7Non-console administrative access encrypted
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
2.3 Wireless environment configuration
2.3.1Wireless vendor defaults changedUnmappedUnmappedUnmappedNot yet
2.3.2Wireless encryption key changesUnmappedUnmappedUnmappedNot yet
3.1 Stored data protection processes and roles
3.1.1Stored account data policies and procedures
Controls: BIZ-14, DATA-04
PassingNot currentNot approvedNot yet
3.1.2Stored account data roles and responsibilities
Controls: BIZ-15
PassingNot currentNot approvedNot yet
3.2 Account data storage minimization
3.2.1Data retention and disposal
Controls: DATA-04, DATA-05
PassingNot currentNot approvedNot yet
3.3 Sensitive authentication data after authorization
3.3.1SAD not retained after authorizationUnmappedUnmappedUnmappedNot yet
3.3.2Pre-authorization SAD encryptedUnmappedUnmappedUnmappedNot yet
3.3.3Issuer SAD storageUnmappedUnmappedUnmappedNot yet
3.4 PAN display and copy restrictions
3.4.1PAN maskingUnmappedUnmappedUnmappedNot yet
3.4.2PAN copy through remote access preventedUnmappedUnmappedUnmappedNot yet
3.5 PAN secured in storage
3.5.1PAN rendered unreadable
Controls: DATA-02
PassingNot currentNot approvedNot yet
3.6 Protection of cryptographic keys
3.6.1Key protection procedures
Controls: DATA-06
Not passingNot currentNot approvedNot yet
3.7 Key lifecycle management
3.7.1Strong key generation
Controls: DATA-06
Not passingNot currentNot approvedNot yet
3.7.2Secure key distributionUnmappedUnmappedUnmappedNot yet
3.7.3Secure key storageUnmappedUnmappedUnmappedNot yet
3.7.4Key changes at end of cryptoperiodUnmappedUnmappedUnmappedNot yet
3.7.5Key retirement and replacement
Controls: DATA-06
Not passingNot currentNot approvedNot yet
3.7.6Split knowledge and dual controlUnmappedUnmappedUnmappedNot yet
3.7.7Unauthorized key substitution preventedUnmappedUnmappedUnmappedNot yet
3.7.8Key custodian acknowledgment
Controls: PEOPLE-04
PassingCurrentApproved(4 mo ago)
3.7.9Customer key guidance (service providers)UnmappedUnmappedUnmappedNot yet
4.1 Transmission protection processes and roles
4.1.1Transmission security policies and procedures
Controls: BIZ-14, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
4.1.2Transmission security roles and responsibilities
Controls: BIZ-15, DATA-03
PassingNot currentNot approved(8 h ago)
4.2 PAN protection during transmission
4.2.1Strong cryptography for PAN in transit
Controls: CLOUD-01, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
4.2.2PAN in end-user messaging
Controls: DATA-01
PassingNot currentNot approvedNot yet
5.1 Anti-malware processes and roles
5.1.1Anti-malware policies and procedures
Controls: BIZ-14
PassingNot currentNot approvedNot yet
5.1.2Anti-malware roles and responsibilities
Controls: BIZ-15
PassingNot currentNot approvedNot yet
5.2 Malware prevention and detection
5.2.1Anti-malware deployedUnmappedUnmappedUnmappedNot yet
5.2.2Malware detection and removalUnmappedUnmappedUnmappedNot yet
5.2.3Evaluation of systems not at risk
Controls: CLOUD-04
PassingNot currentApprovedNot yet
5.3 Anti-malware operation and monitoring
5.3.1Automatic anti-malware updatesUnmappedUnmappedUnmappedNot yet
5.3.2Scanning or behavioral analysisUnmappedUnmappedUnmappedNot yet
5.3.3Removable media scanningUnmappedUnmappedUnmappedNot yet
5.3.4Anti-malware audit logs
Controls: MON-01
Not passingNot currentNot approved(3 mo ago)
5.3.5Anti-malware cannot be disabledUnmappedUnmappedUnmappedNot yet
5.4 Anti-phishing
5.4.1Phishing detection and protectionUnmappedUnmappedUnmappedNot yet
6.1 Secure development processes and roles
6.1.1Secure development policies and procedures
Controls: BIZ-14
PassingNot currentNot approvedNot yet
6.1.2Secure development roles and responsibilities
Controls: BIZ-15
PassingNot currentNot approvedNot yet
6.2 Secure software development
6.2.1Secure development of bespoke software
Controls: APP-01
PassingCurrentApproved(4 mo ago)
6.2.2Annual developer security training
Controls: APP-01
PassingCurrentApproved(4 mo ago)
6.2.3Pre-release code review
Controls: APP-02, PDP-03
Not passingNot currentNot approved(8 h ago)
6.2.4Prevention of common software attacks
Controls: APP-01, APP-02
Not passingNot currentApproved(3 mo ago)
6.3 Vulnerability identification and remediation
6.3.1Vulnerability identification and risk ranking
Controls: MON-05, MON-06
Not passingNot currentNot approved(3 mo ago)
6.3.2Software component inventoryUnmappedUnmappedUnmappedNot yet
6.3.3Security patching timelines
Controls: CLOUD-05, IT-03, MON-06
Not passingNot currentNot approved(8 h ago)
6.4 Public-facing web application protection
6.4.1Web application assessment or protectionUnmappedUnmappedUnmappedNot yet
6.4.2Automated web attack preventionUnmappedUnmappedUnmappedNot yet
6.4.3Payment page script managementUnmappedUnmappedUnmappedNot yet
6.5 Secure change management
6.5.1Change control procedures
Controls: PDP-02, PDP-03, PDP-14
Not passingNot currentNot approved(8 h ago)
6.5.2Post-change PCI DSS confirmation
Controls: PDP-14
PassingCurrentApproved(4 mo ago)
6.5.3Pre-production separated from production
Controls: CLOUD-06
PassingCurrentApproved(29 d ago)
6.5.4Separation of duties for deployment
Controls: PDP-05
PassingCurrentNot approved(29 d ago)
6.5.5No live PAN in pre-productionUnmappedUnmappedUnmappedNot yet
6.5.6Test data removed before production
Controls: CLOUD-06
PassingCurrentApproved(29 d ago)
7.1 Access restriction processes and roles
7.1.1Access restriction policies and procedures
Controls: BIZ-14, IAM-04
PassingNot currentNot approved(29 d ago)
7.1.2Access restriction roles and responsibilities
Controls: BIZ-15, IAM-04
PassingNot currentNot approved(29 d ago)
7.2 Access definition and assignment
7.2.1Access control model
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
7.2.2Least-privilege assignment
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
7.2.3Privilege approval
Controls: IAM-07
Not passingCurrentNot approved(29 d ago)
7.2.4Semiannual user access review
Controls: IAM-09
PassingCurrentNot approved(29 d ago)
7.2.5Application and system account privileges
Controls: IAM-04
PassingNot currentNot approved(29 d ago)
7.2.6Query access to stored cardholder dataUnmappedUnmappedUnmappedNot yet
7.3 Access control systems
7.3.1Need-to-know access control system
Controls: IAM-01, IAM-05
PassingNot currentNot approved(29 d ago)
7.3.2Permissions enforced by job function
Controls: IAM-05
PassingNot currentNot approved(29 d ago)
7.3.3Deny all by default
Controls: IAM-04, IAM-05
PassingNot currentNot approved(29 d ago)
8.1 Identification and authentication processes and roles
8.1.1Identification and authentication policies and procedures
Controls: BIZ-14, IAM-01
PassingNot currentNot approved(29 d ago)
8.1.2Identification and authentication roles and responsibilities
Controls: BIZ-15, IAM-01
PassingNot currentNot approved(29 d ago)
8.2 User identification and account lifecycle
8.2.1Unique user IDsUnmappedUnmappedUnmappedNot yet
8.2.2Shared and generic IDs restricted
Controls: IAM-03
PassingCurrentNot approved(29 d ago)
8.2.3Unique factors per customer (service providers)UnmappedUnmappedUnmappedNot yet
8.2.4Authorized identity lifecycle changes
Controls: IAM-07
Not passingCurrentNot approved(29 d ago)
8.2.5Immediate revocation on termination
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
8.2.6Inactive accounts disabled within 90 days
Controls: IAM-09
PassingCurrentNot approved(29 d ago)
8.2.7Third-party remote access accountsUnmappedUnmappedUnmappedNot yet
8.2.815-minute idle session timeoutUnmappedUnmappedUnmappedNot yet
8.3 Strong authentication
8.3.1Authentication factor required
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
8.3.2Authentication factors encrypted
Controls: DATA-03, IAM-01
PassingCurrentNot approved(8 h ago)
8.3.3Identity verified before factor changesUnmappedUnmappedUnmappedNot yet
8.3.4Account lockout after failed attemptsUnmappedUnmappedUnmappedNot yet
8.3.5Unique initial and reset passwords
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
8.3.6Password length and complexity
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
8.3.7Password history of four
Controls: IAM-08
PassingNot currentNot approved(8 h ago)
8.3.8Authentication guidance for users
Controls: IAM-03, PEOPLE-06
Not passingCurrentNot approved(8 h ago)
8.3.9Single-factor password rotation
Controls: IAM-02, IAM-08
Not passingNot currentNot approved(8 h ago)
8.3.10Customer password guidance (service providers)
Controls: CUST-03
PassingNot currentApprovedNot yet
8.3.11Tokens and certificates not sharedUnmappedUnmappedUnmappedNot yet
8.4 MFA into the CDE
8.4.1MFA for administrative CDE access
Controls: IAM-02, IAM-06
Not passingNot currentNot approved(8 h ago)
8.4.2MFA for all CDE access
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
8.4.3MFA for remote network access
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
8.5 MFA system configuration
8.5.1MFA resistant to misuse
Controls: IAM-02
Not passingNot currentNot approved(8 h ago)
8.6 Application and system account management
8.6.1Interactive use of system accountsUnmappedUnmappedUnmappedNot yet
8.6.2No hard-coded passwords
Controls: APP-01
PassingCurrentApproved(4 mo ago)
8.6.3System account password protection
Controls: IAM-03
PassingCurrentNot approved(29 d ago)
9.1 Physical security processes and roles
9.1.1Physical security policies and procedures
Controls: BIZ-14, PHYS-01
PassingNot currentNot approvedNot yet
9.1.2Physical security roles and responsibilities
Controls: BIZ-15, PHYS-01
PassingNot currentNot approvedNot yet
9.2 Facility and system physical access controls
9.2.1Facility entry controls
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.2.2Publicly accessible network jacks restricted
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.2.3Network hardware access restricted
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.2.4Consoles locked when not in use
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.3 Personnel and visitor physical access
9.3.1Personnel physical access procedures
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.3.2Visitor access procedures
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.3.3Visitor badges surrendered
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.3.4Visitor log
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.4 Media with cardholder data
9.4.1Media physically secured
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.4.2Media classified by sensitivity
Controls: DATA-01
PassingNot currentNot approvedNot yet
9.4.3Media sent offsite securedUnmappedUnmappedUnmappedNot yet
9.4.4Management approval for media movementUnmappedUnmappedUnmappedNot yet
9.4.5Electronic media inventory logs
Controls: IT-04
PassingNot currentNot approvedNot yet
9.4.6Hard-copy destructionUnmappedUnmappedUnmappedNot yet
9.4.7Electronic media destruction
Controls: PHYS-01
PassingNot currentNot approvedNot yet
9.5 POI device protection
9.5.1POI tampering and substitution protectionUnmappedUnmappedUnmappedNot yet
10.1 Logging processes and roles
10.1.1Logging and monitoring policies and procedures
Controls: BIZ-14, MON-01
Not passingNot currentNot approved(3 mo ago)
10.1.2Logging and monitoring roles and responsibilities
Controls: BIZ-15, MON-03
Not passingNot currentNot approved(3 mo ago)
10.2 Audit log implementation
10.2.1Audit logging enabled
Controls: MON-01, MON-02
Not passingNot currentNot approved(3 mo ago)
10.2.2Audit log event detailsUnmappedUnmappedUnmappedNot yet
10.3 Audit log protection
10.3.1Log read access restrictedUnmappedUnmappedUnmappedNot yet
10.3.2Logs protected from modificationUnmappedUnmappedUnmappedNot yet
10.3.3Central log backup
Controls: MON-01
Not passingNot currentNot approved(3 mo ago)
10.3.4Log integrity monitoringUnmappedUnmappedUnmappedNot yet
10.4 Audit log review
10.4.1Daily review of critical logs
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
10.4.2Periodic review of other logs
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
10.4.3Log exceptions addressed
Controls: BIZ-03, MON-03
Not passingNot currentNot approved(8 h ago)
10.5 Audit log retention
10.5.112-month log retentionUnmappedUnmappedUnmappedNot yet
10.6 Time synchronization
10.6.1Clock synchronization technologyUnmappedUnmappedUnmappedNot yet
10.6.2Correct and consistent timeUnmappedUnmappedUnmappedNot yet
10.6.3Time settings protectedUnmappedUnmappedUnmappedNot yet
10.7 Critical security control failures
10.7.1Control failure detection (service providers)UnmappedUnmappedUnmappedNot yet
10.7.2Control failure detectionUnmappedUnmappedUnmappedNot yet
10.7.3Control failure response
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
11.1 Security testing processes and roles
11.1.1Security testing policies and procedures
Controls: BIZ-14, MON-04, MON-05
Not passingNot currentNot approved(8 h ago)
11.1.2Security testing roles and responsibilities
Controls: BIZ-15, MON-05
Not passingNot currentNot approved(3 mo ago)
11.2 Wireless access point management
11.2.1Wireless access point detectionUnmappedUnmappedUnmappedNot yet
11.2.2Authorized wireless access point inventory
Controls: IT-04
PassingNot currentNot approvedNot yet
11.3 Vulnerability scanning
11.3.1Quarterly internal vulnerability scans
Controls: MON-05, MON-06
Not passingNot currentNot approved(3 mo ago)
11.3.2Quarterly ASV external scansUnmappedUnmappedUnmappedNot yet
11.4 Penetration testing
11.4.1Penetration testing methodology
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
11.4.2Internal penetration testing
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
11.4.3External penetration testing
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
11.4.4Penetration test findings corrected
Controls: BIZ-09, MON-04, MON-06
Not passingNot currentNot approved(8 h ago)
11.4.5Segmentation control testing
Controls: MON-04
Not passingCurrentNot approved(8 h ago)
11.4.6Semiannual segmentation testing (service providers)UnmappedUnmappedUnmappedNot yet
11.4.7Customer penetration testing support (multi-tenant providers)UnmappedUnmappedUnmappedNot yet
11.5 Intrusion and change detection
11.5.1Intrusion detection and preventionUnmappedUnmappedUnmappedNot yet
11.5.2Change detection on critical filesUnmappedUnmappedUnmappedNot yet
11.6 Payment page change detection
11.6.1Payment page tamper detectionUnmappedUnmappedUnmappedNot yet
12.1 Information security policy
12.1.1Information security policy established
Controls: BIZ-14
PassingNot currentNot approvedNot yet
12.1.2Annual policy review
Controls: BIZ-14
PassingNot currentNot approvedNot yet
12.1.3Security roles defined and acknowledged
Controls: BIZ-15, PEOPLE-04, PEOPLE-08
Not passingNot currentNot approved(4 mo ago)
12.1.4Executive responsibility for security
Controls: BIZ-11, BIZ-12, BIZ-15
PassingNot currentNot approvedNot yet
12.2 Acceptable use
12.2.1Acceptable use policies
Controls: IT-01
PassingNot currentApprovedNot yet
12.3 Risk identification and management
12.3.1Targeted risk analysis
Controls: BIZ-04, BIZ-05
PassingNot currentNot approved(4 mo ago)
12.3.2Customized approach risk analysisUnmappedUnmappedUnmappedNot yet
12.3.3Cipher suite and protocol review
Controls: DATA-06
Not passingNot currentNot approvedNot yet
12.3.4Hardware and software technology reviewUnmappedUnmappedUnmappedNot yet
12.4 PCI DSS compliance management
12.4.1Executive compliance accountability (service providers)
Controls: BIZ-11, BIZ-12, BIZ-15
PassingNot currentNot approvedNot yet
12.4.2Quarterly operational reviews (service providers)
Controls: BIZ-08
PassingNot currentApprovedNot yet
12.5 Scope documentation and validation
12.5.1In-scope system inventory
Controls: IT-04, IT-05
PassingNot currentNot approvedNot yet
12.5.2Annual scope confirmationUnmappedUnmappedUnmappedNot yet
12.5.3Organizational change scope review (service providers)UnmappedUnmappedUnmappedNot yet
12.6 Security awareness
12.6.1Security awareness program
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
12.6.2Annual awareness program review
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
12.6.3Awareness training and policy acknowledgment
Controls: PEOPLE-04, PEOPLE-06
Not passingCurrentApproved(8 h ago)
12.7 Personnel screening
12.7.1Pre-hire screening
Controls: PEOPLE-01
Not passingCurrentNot approved(4 mo ago)
12.8 Third-party service provider risk
12.8.1TPSP list
Controls: VEND-01
PassingNot currentNot approvedNot yet
12.8.2TPSP written agreements
Controls: VEND-02
PassingNot currentNot approvedNot yet
12.8.3TPSP due diligence
Controls: VEND-03
PassingNot currentNot approvedNot yet
12.8.4Annual TPSP compliance monitoring
Controls: VEND-04
Not passingCurrentNot approved(8 h ago)
12.8.5TPSP responsibility matrixUnmappedUnmappedUnmappedNot yet
12.9 TPSP support for customer compliance
12.9.1Written responsibility acknowledgment (service providers)
Controls: CUST-02
PassingNot currentApprovedNot yet
12.9.2Compliance information for customers (service providers)UnmappedUnmappedUnmappedNot yet
12.10 Incident response
12.10.1Incident response plan
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
12.10.2Annual plan review and test
Controls: BIZ-02, BIZ-21
PassingNot currentNot approved(3 mo ago)
12.10.324/7 incident response personnel
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)
12.10.4Incident response training
Controls: BIZ-21
PassingCurrentApproved(4 mo ago)
12.10.5Security alert monitoring in the plan
Controls: BIZ-02, MON-03
Not passingNot currentNot approved(3 mo ago)
12.10.6Plan updated with lessons learned
Controls: BIZ-02, BIZ-09
PassingNot currentNot approved(3 mo ago)
12.10.7Response to unexpected stored PAN
Controls: BIZ-02
PassingNot currentNot approved(3 mo ago)