Skip to main content

Pro audit program · v1.0

PCI-DSS Quick Scope

Even if you are a SAQ-A merchant, a quick check of CHD scope, segmentation, vendor responsibilities and key PCI controls.

  • General target area
  • PCI-DSS v4 framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Even if you are a SAQ-A merchant, a quick check of CHD scope, segmentation, vendor responsibilities and key PCI controls.

Risks addressed

  • Critical Cardholder data stored where you did not expect
  • Critical Untested segmentation makes the whole network in-scope
  • High Third-party payment page not validated PCI-compliant

Controls (7)

  1. Documented scope + data-flow diagram

    Critical

    Documented scope + data-flow diagram

    How to test + evidence

    Testing procedure: Current CHD flow diagram, dated within 12 months.

    Evidence to collect: CHD diagram.

  2. No storage of full PAN / SAD beyond what is allowed

    Critical

    No storage of full PAN / SAD beyond what is allowed

    How to test + evidence

    Testing procedure: Scan systems for PAN; track-2 / CVV never stored.

    Evidence to collect: Scan report.

  3. Segmentation tested annually

    High

    Segmentation tested annually

    How to test + evidence

    Testing procedure: Segmentation pen-test confirms isolation from non-CDE.

    Evidence to collect: Pen-test report.

  4. Payment provider attestation on file

    High

    Payment provider attestation on file

    How to test + evidence

    Testing procedure: AoC from PSP confirming their PCI compliance.

    Evidence to collect: AoC document.

  5. MFA on all CDE access

    Critical

    MFA on all CDE access

    How to test + evidence

    Testing procedure: MFA for all admin + remote access to CDE.

    Evidence to collect: MFA evidence.

  6. Critical patches within 30 days for CDE

    High

    Critical patches within 30 days for CDE

    How to test + evidence

    Testing procedure: Patch SLA met on every CDE system.

    Evidence to collect: Patch report.

  7. Quarterly external + internal scans

    High

    Quarterly external + internal scans

    How to test + evidence

    Testing procedure: ASV + internal vuln scans run quarterly with rescans on findings.

    Evidence to collect: Scan reports.