ZenGRC

PCI DSS: Testing Controls and Gathering Evidence

The content explains that PCI DSS compliance is a continuous, rigorous process requiring organizations to regularly test and document security controls around cardholder data, remediate issues, and provide current evidence to Qualified Security Assessors to avoid costly fines, audit failures, and loss of credit card processing privileges, emphasizing best practices such as frequent testing, annual audits, quarterly scans, and thorough documentation.

Compliance with the Payment Card Industry Data Security Standard (PCI DSS) is challenging. According to a 2017 Verizon report, 80 percent of companies fail their PCI DSS assessments, and only 29 percent of those that pass remain compliant after one year.

PCI DSS compliance, like information security as a whole, is an ongoing process. Vigilance is required to maintain compliance and avoid significant penalties for non-compliance. With proper planning and preparation, organizations can obtain a Report on Compliance (ROC) or Attestation of Compliance (AOC).

Before every PCI DSS audit or self-assessment, organizations must:

  • Test the controls around the cardholder data environment (CDE)
  • Remediate any issues found
  • Collect evidence that security policies are functioning as intended

Best practices for maintaining PCI DSS compliance include:

  • Frequent testing of organizational system and security controls
  • Annual on-site audits or assessments
  • Quarterly scans of systems by an Approved Scan Vendor (ASV)
  • Documentation of policies, procedures, and activities involving the processing, storage, and transmission of credit card or cardholder data
  • Documentation of systems and controls testing

After completing these steps, present the test results and evidence of PCI compliance efforts to the Qualified Security Assessor (QSA) conducting the audit. Failure to do so may result in:

  • Higher audit costs if the auditor must perform the tests and collect evidence
  • Costly fines for non-compliance if the audit or self-assessment is failed
  • Loss of the ability to accept credit card payments

Evidence provided must be current, even if tests have been run previously.

What is PCI DSS, and Why Does It Matter?

PCI DSS was established by the PCI Security Standards Council (PCI SSC), a consortium led by Visa, Discover, JCB, Mastercard, and American Express. It is a set of data security standards that all merchants and service providers must meet if they process credit card data. The framework aims to secure credit card and cardholder data from breaches. Acquiring banks require continuous compliance from merchants and relevant service providers. Regular, end-to-end testing of payment systems is essential to meet these requirements.

How Do I Test Controls and Gather Evidence?

Controls to be tested focus on the security of the entire payment card transaction network, including:

  • Point-of-sale systems
  • Applications processing payment information
  • Data storage methods
  • Network security of routers transmitting information
  • Encryption of sensitive data

Key steps include:

  • Risk assessment: Assess risk organization-wide, specifically addressing credit card data risk, and document remediation efforts.
  • PCI DSS requirements: There are 281 requirements in 12 categories, covering encryption (e.g., using TLS instead of SSL), network segmentation, third-party vendor security, security awareness training, data disposal, and more.
  • Penetration testing: Required throughout the CDE, performed by internal staff or independent third parties. Includes vulnerability scans to identify security gaps.
  • Segmentation testing: Required annually if the CDE is segmented from the rest of the network. Verifies that segmentation methods are effective and isolates CDE systems from out-of-scope systems.

After testing and verification, prepare an audit trail of documents demonstrating PCI compliance efforts. Documentation may include:

  • Emails
  • System and network logs
  • Policies and procedures
  • Protocols
  • Network configurations
  • System architectures
  • Other written materials showing CDE security

Get Help if You Need It

Achieving PCI DSS compliance can take at least two years for larger companies and a year or more for smaller ones. Relying on spreadsheets to track directives and compliance status is inefficient.

Modern solutions, such as ZenGRC, offer software as a service to scan systems against PCI DSS directives, identify compliance gaps, and provide a dashboard for easy tracking. ZenGRC enables frequent audits, remediation of issues, and organizes all necessary documentation for audits, allowing organizations to focus on maintaining secure systems and satisfied customers.

Worry-free, hassle-free PCI DSS compliance is achievable with the right tools and preparation.