PCI DSS is probably the most critical compliance standard your organization will need to comply with if your organization processes payment card transactions or has customers who process payment card transactions. If your organization does not comply with PCI, you may lose authorization to process these transactions or, if you don’t process transactions, you may lose the business of customers who rely on your service for their own transaction processing activities. Part of complying with PCI will involve producing significant amounts of documentation related to managing your IT environment. This documentation will be used to support your answers if you are filling out a PCI DSS Self-Assessment Questionnaire (SAQ) or support your auditor’s testing if you are required to have a PCI on-site assessment performed (QSA assessment or Report on Compliance (ROC)).
To help determine what documentation is required when completing a PCI SAQ or ROC, we have read through PCI SAQ D, the assessment guidance for PCI ROCs, and outside sources.
The table below contains the documentation required for each of the 12 PCI DSS requirements outlined by the PCI Security Standards Council.
PCI Requirement | Documentation Required |
1. Install and maintain a firewall configuration to protect cardholder data |
|
2. Do not use vendor-supplied defaults for system passwords and other security parameters |
|
3. Protect stored cardholder data |
|
4. Encrypt transmission of cardholder data across open, public networks |
|
5. Protect all systems against malware and regularly update anti-virus software or programs |
|
6. Develop and maintain secure systems and applications |
|
7. Restrict access to cardholder data by business need-to-know |
|
8. Identify and authenticate access to system components |
|
9. Restrict physical access to cardholder data |
|
10. Track and monitor all access to network resources and cardholder data |
|
11. Regularly test security systems and processes |
|
12. Maintain a policy that addresses information security for all personnel |
|
This article was developed through the use of the following website: https://www.pcidssguide.com/pci-dss-policy-and-procedure-documentation/ along with consulting the assessor guidance provided by the PCI Security Standard Council.