PCI Report on Compliance

April 7, 2012
39 Views

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.

The PCI Security Standards Council provides a template for an attestation of compliance:

Executive Summary

  • Entity’s payment card business description
  • High level network diagram

Description of Scope of Work and Approach Taken

  • How the assessment was made
  • Environment
  • Network segmentation used
  • Details for each sample set tested
  • Any international entities requiring compliance with PCI DSS
  • Wireless networks or applications
  • Version of PCI DSS used to conduct assessment (2.0 is the latest)

Details About Reviewed Environment

  • Network diagrams
  • Cardholder data environment
  • List of hardware and software in the cardholder data environment (CDE)
  • Service providers
  • Third-party applications
  • Individuals interviewed
  • Documentation reviewed
  • Reviews of managed service providers

Contact Information and Reporting Date

Quarterly Scan Results

  • Including the four most recent ASV (approved scanning vendor) scan results

Findings and Observations

  • Requirements and sub-requirements
  • Explain N/A responses
  • Validation of all compensating controls

When it comes to documenting details about your reviewed environment, any of your managed service providers/PCI hosting providers should be able to produce their own attestation of compliance report to inform your company about their controls and security. This can save you the time it takes to review and report on their compliance as it affects your company and cardholder data.

References:
PCI DSS Quick Reference Guide (Version 2.0) (PDF)

You may be interested

Can Natural Remedies Like RediCalm Decrease Stress and Anxiety?
Wellness
2 views
Wellness
2 views

Can Natural Remedies Like RediCalm Decrease Stress and Anxiety?

Ryan Kh - August 16, 2017

According to research from the National Institute of Mental Health, anxiety disorders are the most common mental illness in the…

How to Alleviate Stress Related Insomnia
Specialties
400 views
Specialties
400 views

How to Alleviate Stress Related Insomnia

JohnHenning - August 15, 2017

Do you have difficulty falling asleep or staying asleep every night? You aren't alone. According to multiple studies, including one…

4 Hormones That Play a Critical Role in Your Well being
Wellness
437 views
Wellness
437 views

4 Hormones That Play a Critical Role in Your Well being

Erica - August 15, 2017

Hormonal health and wellbeing have received plenty of attention lately, both from the medical community as well as from health-conscious…