ZenGRC

PCI DSS Security Audit Procedures

The PCI DSS Security Audit Procedures, conducted by qualified security assessors, evaluate organizations that store, process, or transmit credit card data for compliance with PCI DSS standards administered by the PCI SSC, while also considering the complementary PA-DSS requirements focused on payment applications' security controls, with audits structured to assess adherence to data protection mandates excluding operating systems and back-office systems.

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard designed for organizations that store, process, or transmit credit cards and are exposed to cardholder data. The standard is administered by the Payment Card Industry Security Standards Council (PCI SSC) and is advocated by the card brands themselves. Organizations interested in compliance often ask, “what are the PCI DSS Security Audit Procedures?”

PCI DSS Audit Procedures

The PCI DSS Audit Procedures are intended for use by a qualified security assessor (QSA) conducting an audit on merchants or service providers required to validate compliance with the PCI data security standard. The payment card industry has outlined requirements in the data security standard, which detail how to obtain PCI compliance. In addition to PCI DSS, there is also the Payment Application Data Security Standard (PA-DSS), which applies to all PCI-approved payment applications. Payment applications must adhere to specific security requirements, including:

  1. 1.Applications must not store full magnetic stripe or card data.
  2. 2.Applications that require disabling other security countermeasures like antivirus or firewalls are not PCI DSS or PA-DSS compliant.
  3. 3.Vendors that use unsecured methods to connect to payment card applications are not PCI DSS or PA-DSS compliant.

PA-DSS complements PCI DSS requirements but has a more focused scope on applications. PA-DSS does not evaluate the operating system the application runs on, nor does it examine the database for security countermeasures. Back office systems are also outside the scope of data security standards. PA-DSS applies to:

  1. 1.All payment card application functionality
  2. 2.The guidance that the payment card application provides customers and potential customers
  3. 3.Selected platforms and application versions
  4. 4.Tools used by or within the application

PCI DSS Security Audit Report Structure

When a QSA conducts the PCI DSS Security Audit, they must prepare a report to validate their findings. The PCI Security Standards Council provides a sample report outlining all components of the audit procedures, which merchants or service providers can use as an audit plan template before an audit. The report is broken down into the following sections:

  1. 1.Description of scope of the review (what is being assessed)
  2. 2.Executive Summary (high-level overview of the environment, applications, systems, and people)
  3. 3.Findings and Observations (what the auditor found and observed in the audit)
  4. 4.Contact information and report date (who was interviewed and when the report was finished)

The security audit procedures include a checklist created by the PCI Security Standards Council. The checklist includes columns that capture the requirement, testing procedures, whether the control is in place or not, target date, and comments.

Purpose and Benefits of PCI DSS Compliance

PCI DSS compliance is designed to protect credit cardholders and credit card data. The standard represents solid information security practices, encourages security policy, and encompasses both traditional business and e-commerce. Organizations seek a Report on Compliance (RoC) to prove they have a secure network. Achieving compliance involves following cybersecurity basics such as access controls, anti-virus software, vulnerability management, and conducting risk assessments, especially when interfacing with public networks. Penetration testing can help in pre-PCI audit scenarios where merchants and service providers want visibility into potential weak spots in the PCI network. The Self-Assessment Questionnaires (SAQs) are used by lower-level merchants (with fewer transactions) to perform a self-assessment of their compliance. Merchants are classified into levels based on the number of transactions processed in a given year.

The PCI DSS audit procedures assist the QSA in performing specific audit testing steps while providing guidance for merchants and service providers on how they will be assessed.