simpl.
Cybersecurity GRC 20 items

PCI DSS 4.0 Compliance Assessment

Assesses cardholder data environment controls against the twelve PCI DSS v4.0 requirements for protecting account data.

PCI DSS 4.0

Free PDF · enter your email to download.

Protect Networks & Systems (Req 1-2)

  • Are network security controls (firewalls) installed and configured to restrict traffic to the CDE? *
  • Are vendor-supplied defaults changed and unnecessary accounts removed before installation? *
  • Is an inventory of system components in scope maintained? *

Protect Account Data (Req 3-4)

  • Is stored account data kept to a minimum with a documented retention/disposal policy? *
  • Is the Primary Account Number (PAN) rendered unreadable wherever stored? *
  • Is sensitive authentication data never stored after authorization? *
  • Is PAN protected with strong cryptography during transmission over open, public networks? *

Vulnerability Management (Req 5-6)

  • Is anti-malware deployed and kept current on applicable systems? *
  • Are security patches installed within defined timeframes based on risk? *
  • Are public-facing web applications protected against attacks (WAF or review)? *

Access Control (Req 7-9)

  • Is access to system components and cardholder data restricted by business need to know? *
  • Is MFA implemented for all access into the CDE? *
  • Are unique IDs assigned to each user with access to system components? *
  • Is physical access to the CDE restricted and monitored? *

Monitoring & Testing (Req 10-11)

  • Are audit logs enabled to link access to individual users and reviewed regularly? *
  • Are internal and external vulnerability scans performed at least quarterly? *
  • Is external and internal penetration testing performed at least annually? *

Security Policy (Req 12)

  • Is a comprehensive information security policy maintained and reviewed at least annually? *
  • Is a targeted risk analysis performed for applicable requirements? *
  • Is an incident response plan established and tested? *

Download the full PCI DSS 4.0 Compliance Assessment checklist

Get it as a clean, printable PDF — free.