PCI Policies, Procedures and Evidence – What is expected?

Alastair Stewart
|
Senior Consultant at URM
|
|
PUBLISHED on
08
August
2022
SUMMARY

While it’s one of the areas that IT and security departments find challenging, documentation (and compliant evidence) is what makes for a happy and satisfied PCI Qualified Security Assessor (QSA), and, more importantly, a successful PCI compliance audit!  Successful compliance programmes invariably depend on the accurate and consistent recording of events and the adherence to well-defined policies and procedures.

These documents ensure all staff are aware of their obligations, as well as defining the necessary actions to ensure a secure and compliant environment is achieved. With a number of PCI requirements, certain documents will need to be reviewed periodically or the instructions contained therein carried out at specific intervals.  

If the actions in question (i.e. firewall rule reviews / external vulnerability scans) are not performed as instructed, the entire compliance initiative may be jeopardised.  Organisations are well-advised to analyse their documentation and evidentiary requirements and summarise these centrally, where the content and resulting actions can be tracked.  

Security policies and procedures are not a new concept and, coupled with the multitude of security standards that have been developed over the past few decades, there’s no need to start from scratch and be overly creative.  

As long as the documents are clear, concise, deliver the intended message, are customised to the environment in question and elicit the necessary behaviour, the document set will achieve the desired outcome.   It is essential that you ensure all PCI control statements which require explicit documentation are included in the relevant documents.  This will save you both time and resources when addressing this necessary, albeit challenging, task.

The list of documents and evidence artefacts that act as the baseline for achieving compliance with the PCI DSS is very extensive.

Not all documents will be obligatory for all organisations, however, a significant number will need to have been implemented in order for a successful outcome to be achieved.  If these documents, procedures and activities geared towards producing the necessary evidence are in place, you are well on the way to attaining compliance.  To illustrate the type of documents and evidence (by no means exhaustive!) you will typically need to develop and implement, here is starter for ten!:

Documents

  1. Network device management policy
  2. Wireless scanning procedure (rogue access points)
  3. Remote access policy (staff/vendor)
  4. Device configuration standards
  5. Visitor policy
  6. Operational security procedures

Evidence

  1. Network diagrams
  2. Dataflow diagrams
  3. Incident response test
  4. Role-based access matrix
  5. Vulnerability scans
  6. Risk register
  7. Third party contracts (soft copy)

Alastair Stewart
Alastair Stewart
Senior Consultant at URM
Alastair is one of the most experienced and proficient Payment Card Industry Qualified Security Assessors (PCI QSAs) in the UK. He has completed in excess of one hundred successful reports on compliance (RoCs) against different PCI DSS versions along with supporting the completion of self-assessment questionnaires (SAQs).

Do you need support in meeting your annual PCI DSS penetration testing requirements?

As a CREST-accredited penetration testing organisation, URM can complete internal and external penetration tests.
Thumbnail of the Blog Illustration
Information Security
Published on
21/6/2022
PCI SSC Remote Assessment Guidelines and Procedures

We address a number of key questions: What are the Main Contents? What Led to it Being Published? And others.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
15/2/2023
PCI DSS v4.0 and Multi-Factor Authentication

After the recent changes to PCI DSS v4.0 we're examining factors behind the greater utilisation of MFA, and what the key changes are in requirements.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
5/8/2022
PCI DSS compliance as BAU (business as usual)

For an organisation to achieve and maintain compliance to the Payment Card Industry Data Security Standard (PCI DSS)....

Read more
We used URM as we had a large amount of information to redact for a Court of Protection case and neither had the time nor the knowledge to be able to complete this appropriately. URM were suggested to us and we made contact. They responded very quickly and were able to explain their role, estimated timescales & costings. During the initial consultation, they were very professional and approachable, and certainly had the skills we required. URM’s consultant provided us with details of the work they had completed before & we felt confident to pursue the work with them. We were on a tight deadline for court and URM were confident that they could provide the services we required in a timely manner. The logistics of sending a large amount of confidential documents were easy to navigate and straightforward. We were unable to very accurately gauge how much work was required, however URM’s Team supported us with this and maintained regular contact regarding their progress and addressed any concerns they had. When we needed to contact them, they were prompt with their responses. The work did take longer that envisaged, however that was due to the amount of work that we, as clients, were unable to accurately identify would be required. We did, however, meet the deadline for court. I would certainly use the services of URM again & if possible would work with same team. The services are not cheap, however redacting sensitive information is a skilled task and, therefore, having a professional complete this work is priceless.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.