POS and store networks
Review POS terminals, store networks, segmentation, remote support, firewall rules, vendor access, and logging.
OC Security Audit helps Orange County and Southern California businesses validate the technical controls behind PCI DSS readiness, including firewalls, segmentation, POS networks, e-commerce payment flows, access control, logging, vulnerability management, vendor access, and incident response.
A PCI DSS technical security assessment reviews the systems, networks, applications, users, vendors, and security controls that support payment card processing. The goal is to determine whether the technical environment is properly segmented, hardened, monitored, patched, encrypted, and protected from unauthorized access.
This assessment supports broader PCI DSS compliance readiness by focusing on the practical controls behind the audit: firewall rules, POS networks, payment websites, administrative access, server configuration, logging, vulnerability management, and incident response readiness.

Businesses often need a PCI DSS technical security assessment when payment systems change, an auditor requests evidence, a merchant needs to reduce scope, a POS or e-commerce environment is unclear, or leadership wants a practical remediation roadmap.
Review POS terminals, store networks, segmentation, remote support, firewall rules, vendor access, and logging.
Review checkout pages, redirects, payment integrations, web servers, APIs, TLS, scanning, and change control.
Validate CDE scope, data flow, access boundaries, encryption, system hardening, logs, and evidence sources.
Assess internet-facing exposure, internal trust zones, Any/Any rules, temporary access, NAT, VPN, and isolation controls.
Review administrative access, MFA, user roles, service accounts, shared accounts, password controls, and privileged activity.
Validate scanning, patching, monitoring, SIEM/log retention, alert ownership, and remediation evidence.
A PCI DSS audit usually evaluates whether required controls are documented and operating. A technical security assessment looks deeper into how payment systems are actually configured, segmented, monitored, patched, accessed, and protected.
Organize the technical evidence that supports audit readiness: diagrams, firewall exports, access reports, scan results, policies, and remediation records.
Review whether the environment is actually protecting cardholder data, not just whether a checklist has an answer.
Translate technical findings into prioritized fixes that business leaders, IT teams, vendors, and assessors can understand.

The deliverable is built for practical action. It separates executive risk from technical detail, highlights scope concerns, documents evidence sources, and gives the IT team specific remediation work.
Identify POS systems, payment applications, e-commerce flow, vendors, networks, firewalls, servers, cloud assets, and CDE boundaries.
Assess firewall rules, segmentation, identity, hardening, vulnerability scanning, logging, monitoring, encryption, and vendor access.
Collect screenshots, exports, diagrams, logs, scan results, policies, tickets, and exception records that support readiness.
Translate findings into a remediation roadmap that separates critical risks from housekeeping items and audit documentation gaps.
This Excel-style review sheet preserves the page’s technical PCI DSS assessment concept while keeping the page professional. Scroll vertically for all rows and horizontally for the full evidence fields. The worksheet is informational and does not collect, submit, store, or process user input.
| # | PCI Area | Technical Control | Environment Reviewed | Evidence To Collect | Risk | Status | Remediation Priority |
|---|---|---|---|---|---|---|---|
| 1 | Requirement 1 Network Security Controls | Scope validation | CDE / firewall / payment flow | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 2 | Requirement 1 Network Security Controls | Evidence review | POS / store network / VPN | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 3 | Requirement 1 Network Security Controls | Configuration sample | E-commerce / web / API | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 4 | Requirement 1 Network Security Controls | Policy alignment | Identity / server / endpoint | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 5 | Requirement 1 Network Security Controls | Operational owner | Logs / vendors / evidence | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 6 | Requirement 1 Network Security Controls | Change history | CDE / firewall / payment flow | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 7 | Requirement 1 Network Security Controls | Risk exception | POS / store network / VPN | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 8 | Requirement 1 Network Security Controls | Monitoring signal | E-commerce / web / API | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 9 | Requirement 1 Network Security Controls | Alert response | Identity / server / endpoint | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 10 | Requirement 1 Network Security Controls | Vendor access | Logs / vendors / evidence | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 11 | Requirement 1 Network Security Controls | Administrative access | CDE / firewall / payment flow | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 12 | Requirement 1 Network Security Controls | Encryption status | POS / store network / VPN | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 13 | Requirement 1 Network Security Controls | Patch status | E-commerce / web / API | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 14 | Requirement 1 Network Security Controls | Vulnerability result | Identity / server / endpoint | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 15 | Requirement 1 Network Security Controls | Segmentation proof | Logs / vendors / evidence | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 16 | Requirement 1 Network Security Controls | Backup and recovery | CDE / firewall / payment flow | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 17 | Requirement 1 Network Security Controls | Incident response | POS / store network / VPN | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 18 | Requirement 1 Network Security Controls | Training or procedure | E-commerce / web / API | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 19 | Requirement 1 Network Security Controls | Management review | Identity / server / endpoint | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 20 | Requirement 1 Network Security Controls | Remediation ticket | Logs / vendors / evidence | Firewall rules, segmentation, inbound exposure, outbound traffic, VPN, NAT, and CDE boundaries. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 21 | Requirement 2 Secure Configurations | Scope validation | CDE / firewall / payment flow | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 22 | Requirement 2 Secure Configurations | Evidence review | POS / store network / VPN | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 23 | Requirement 2 Secure Configurations | Configuration sample | E-commerce / web / API | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 24 | Requirement 2 Secure Configurations | Policy alignment | Identity / server / endpoint | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 25 | Requirement 2 Secure Configurations | Operational owner | Logs / vendors / evidence | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 26 | Requirement 2 Secure Configurations | Change history | CDE / firewall / payment flow | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 27 | Requirement 2 Secure Configurations | Risk exception | POS / store network / VPN | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 28 | Requirement 2 Secure Configurations | Monitoring signal | E-commerce / web / API | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 29 | Requirement 2 Secure Configurations | Alert response | Identity / server / endpoint | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 30 | Requirement 2 Secure Configurations | Vendor access | Logs / vendors / evidence | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 31 | Requirement 2 Secure Configurations | Administrative access | CDE / firewall / payment flow | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 32 | Requirement 2 Secure Configurations | Encryption status | POS / store network / VPN | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 33 | Requirement 2 Secure Configurations | Patch status | E-commerce / web / API | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 34 | Requirement 2 Secure Configurations | Vulnerability result | Identity / server / endpoint | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 35 | Requirement 2 Secure Configurations | Segmentation proof | Logs / vendors / evidence | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 36 | Requirement 2 Secure Configurations | Backup and recovery | CDE / firewall / payment flow | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 37 | Requirement 2 Secure Configurations | Incident response | POS / store network / VPN | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 38 | Requirement 2 Secure Configurations | Training or procedure | E-commerce / web / API | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 39 | Requirement 2 Secure Configurations | Management review | Identity / server / endpoint | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 40 | Requirement 2 Secure Configurations | Remediation ticket | Logs / vendors / evidence | Hardened systems, secure defaults, service review, configuration standards, and change control. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 41 | Requirement 3 Protect Stored Account Data | Scope validation | CDE / firewall / payment flow | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 42 | Requirement 3 Protect Stored Account Data | Evidence review | POS / store network / VPN | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 43 | Requirement 3 Protect Stored Account Data | Configuration sample | E-commerce / web / API | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 44 | Requirement 3 Protect Stored Account Data | Policy alignment | Identity / server / endpoint | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 45 | Requirement 3 Protect Stored Account Data | Operational owner | Logs / vendors / evidence | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 46 | Requirement 3 Protect Stored Account Data | Change history | CDE / firewall / payment flow | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 47 | Requirement 3 Protect Stored Account Data | Risk exception | POS / store network / VPN | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 48 | Requirement 3 Protect Stored Account Data | Monitoring signal | E-commerce / web / API | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 49 | Requirement 3 Protect Stored Account Data | Alert response | Identity / server / endpoint | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 50 | Requirement 3 Protect Stored Account Data | Vendor access | Logs / vendors / evidence | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 51 | Requirement 3 Protect Stored Account Data | Administrative access | CDE / firewall / payment flow | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 52 | Requirement 3 Protect Stored Account Data | Encryption status | POS / store network / VPN | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 53 | Requirement 3 Protect Stored Account Data | Patch status | E-commerce / web / API | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 54 | Requirement 3 Protect Stored Account Data | Vulnerability result | Identity / server / endpoint | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 55 | Requirement 3 Protect Stored Account Data | Segmentation proof | Logs / vendors / evidence | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 56 | Requirement 3 Protect Stored Account Data | Backup and recovery | CDE / firewall / payment flow | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 57 | Requirement 3 Protect Stored Account Data | Incident response | POS / store network / VPN | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 58 | Requirement 3 Protect Stored Account Data | Training or procedure | E-commerce / web / API | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 59 | Requirement 3 Protect Stored Account Data | Management review | Identity / server / endpoint | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 60 | Requirement 3 Protect Stored Account Data | Remediation ticket | Logs / vendors / evidence | Data discovery, retention, encryption, key management, masking, storage review, and deletion. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 61 | Requirement 4 Protect Data In Transit | Scope validation | CDE / firewall / payment flow | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 62 | Requirement 4 Protect Data In Transit | Evidence review | POS / store network / VPN | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 63 | Requirement 4 Protect Data In Transit | Configuration sample | E-commerce / web / API | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 64 | Requirement 4 Protect Data In Transit | Policy alignment | Identity / server / endpoint | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 65 | Requirement 4 Protect Data In Transit | Operational owner | Logs / vendors / evidence | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 66 | Requirement 4 Protect Data In Transit | Change history | CDE / firewall / payment flow | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 67 | Requirement 4 Protect Data In Transit | Risk exception | POS / store network / VPN | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 68 | Requirement 4 Protect Data In Transit | Monitoring signal | E-commerce / web / API | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 69 | Requirement 4 Protect Data In Transit | Alert response | Identity / server / endpoint | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 70 | Requirement 4 Protect Data In Transit | Vendor access | Logs / vendors / evidence | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 71 | Requirement 4 Protect Data In Transit | Administrative access | CDE / firewall / payment flow | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 72 | Requirement 4 Protect Data In Transit | Encryption status | POS / store network / VPN | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 73 | Requirement 4 Protect Data In Transit | Patch status | E-commerce / web / API | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 74 | Requirement 4 Protect Data In Transit | Vulnerability result | Identity / server / endpoint | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 75 | Requirement 4 Protect Data In Transit | Segmentation proof | Logs / vendors / evidence | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 76 | Requirement 4 Protect Data In Transit | Backup and recovery | CDE / firewall / payment flow | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 77 | Requirement 4 Protect Data In Transit | Incident response | POS / store network / VPN | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 78 | Requirement 4 Protect Data In Transit | Training or procedure | E-commerce / web / API | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 79 | Requirement 4 Protect Data In Transit | Management review | Identity / server / endpoint | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 80 | Requirement 4 Protect Data In Transit | Remediation ticket | Logs / vendors / evidence | TLS, certificates, payment integrations, wireless exposure, APIs, and encrypted transmission. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 81 | Requirement 5 Malware Protection | Scope validation | CDE / firewall / payment flow | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 82 | Requirement 5 Malware Protection | Evidence review | POS / store network / VPN | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 83 | Requirement 5 Malware Protection | Configuration sample | E-commerce / web / API | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 84 | Requirement 5 Malware Protection | Policy alignment | Identity / server / endpoint | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 85 | Requirement 5 Malware Protection | Operational owner | Logs / vendors / evidence | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 86 | Requirement 5 Malware Protection | Change history | CDE / firewall / payment flow | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 87 | Requirement 5 Malware Protection | Risk exception | POS / store network / VPN | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 88 | Requirement 5 Malware Protection | Monitoring signal | E-commerce / web / API | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 89 | Requirement 5 Malware Protection | Alert response | Identity / server / endpoint | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 90 | Requirement 5 Malware Protection | Vendor access | Logs / vendors / evidence | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 91 | Requirement 5 Malware Protection | Administrative access | CDE / firewall / payment flow | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 92 | Requirement 5 Malware Protection | Encryption status | POS / store network / VPN | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 93 | Requirement 5 Malware Protection | Patch status | E-commerce / web / API | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 94 | Requirement 5 Malware Protection | Vulnerability result | Identity / server / endpoint | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 95 | Requirement 5 Malware Protection | Segmentation proof | Logs / vendors / evidence | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 96 | Requirement 5 Malware Protection | Backup and recovery | CDE / firewall / payment flow | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 97 | Requirement 5 Malware Protection | Incident response | POS / store network / VPN | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 98 | Requirement 5 Malware Protection | Training or procedure | E-commerce / web / API | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 99 | Requirement 5 Malware Protection | Management review | Identity / server / endpoint | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 100 | Requirement 5 Malware Protection | Remediation ticket | Logs / vendors / evidence | Endpoint protection, anti-malware policy, alert handling, exclusions, and CDE system coverage. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 101 | Requirement 6 Secure Systems And Software | Scope validation | CDE / firewall / payment flow | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 102 | Requirement 6 Secure Systems And Software | Evidence review | POS / store network / VPN | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 103 | Requirement 6 Secure Systems And Software | Configuration sample | E-commerce / web / API | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 104 | Requirement 6 Secure Systems And Software | Policy alignment | Identity / server / endpoint | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 105 | Requirement 6 Secure Systems And Software | Operational owner | Logs / vendors / evidence | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 106 | Requirement 6 Secure Systems And Software | Change history | CDE / firewall / payment flow | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 107 | Requirement 6 Secure Systems And Software | Risk exception | POS / store network / VPN | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 108 | Requirement 6 Secure Systems And Software | Monitoring signal | E-commerce / web / API | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 109 | Requirement 6 Secure Systems And Software | Alert response | Identity / server / endpoint | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 110 | Requirement 6 Secure Systems And Software | Vendor access | Logs / vendors / evidence | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 111 | Requirement 6 Secure Systems And Software | Administrative access | CDE / firewall / payment flow | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 112 | Requirement 6 Secure Systems And Software | Encryption status | POS / store network / VPN | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 113 | Requirement 6 Secure Systems And Software | Patch status | E-commerce / web / API | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 114 | Requirement 6 Secure Systems And Software | Vulnerability result | Identity / server / endpoint | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 115 | Requirement 6 Secure Systems And Software | Segmentation proof | Logs / vendors / evidence | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 116 | Requirement 6 Secure Systems And Software | Backup and recovery | CDE / firewall / payment flow | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 117 | Requirement 6 Secure Systems And Software | Incident response | POS / store network / VPN | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 118 | Requirement 6 Secure Systems And Software | Training or procedure | E-commerce / web / API | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 119 | Requirement 6 Secure Systems And Software | Management review | Identity / server / endpoint | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 120 | Requirement 6 Secure Systems And Software | Remediation ticket | Logs / vendors / evidence | Patch management, vulnerability remediation, secure development, web app review, and change testing. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 121 | Requirement 7 Restrict Access By Need To Know | Scope validation | CDE / firewall / payment flow | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 122 | Requirement 7 Restrict Access By Need To Know | Evidence review | POS / store network / VPN | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 123 | Requirement 7 Restrict Access By Need To Know | Configuration sample | E-commerce / web / API | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 124 | Requirement 7 Restrict Access By Need To Know | Policy alignment | Identity / server / endpoint | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 125 | Requirement 7 Restrict Access By Need To Know | Operational owner | Logs / vendors / evidence | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 126 | Requirement 7 Restrict Access By Need To Know | Change history | CDE / firewall / payment flow | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 127 | Requirement 7 Restrict Access By Need To Know | Risk exception | POS / store network / VPN | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 128 | Requirement 7 Restrict Access By Need To Know | Monitoring signal | E-commerce / web / API | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 129 | Requirement 7 Restrict Access By Need To Know | Alert response | Identity / server / endpoint | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 130 | Requirement 7 Restrict Access By Need To Know | Vendor access | Logs / vendors / evidence | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 131 | Requirement 7 Restrict Access By Need To Know | Administrative access | CDE / firewall / payment flow | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 132 | Requirement 7 Restrict Access By Need To Know | Encryption status | POS / store network / VPN | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 133 | Requirement 7 Restrict Access By Need To Know | Patch status | E-commerce / web / API | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 134 | Requirement 7 Restrict Access By Need To Know | Vulnerability result | Identity / server / endpoint | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 135 | Requirement 7 Restrict Access By Need To Know | Segmentation proof | Logs / vendors / evidence | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 136 | Requirement 7 Restrict Access By Need To Know | Backup and recovery | CDE / firewall / payment flow | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 137 | Requirement 7 Restrict Access By Need To Know | Incident response | POS / store network / VPN | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 138 | Requirement 7 Restrict Access By Need To Know | Training or procedure | E-commerce / web / API | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 139 | Requirement 7 Restrict Access By Need To Know | Management review | Identity / server / endpoint | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 140 | Requirement 7 Restrict Access By Need To Know | Remediation ticket | Logs / vendors / evidence | Role-based access, least privilege, business justification, and access review evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 141 | Requirement 8 Identify Users And Authenticate Access | Scope validation | CDE / firewall / payment flow | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 142 | Requirement 8 Identify Users And Authenticate Access | Evidence review | POS / store network / VPN | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 143 | Requirement 8 Identify Users And Authenticate Access | Configuration sample | E-commerce / web / API | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 144 | Requirement 8 Identify Users And Authenticate Access | Policy alignment | Identity / server / endpoint | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 145 | Requirement 8 Identify Users And Authenticate Access | Operational owner | Logs / vendors / evidence | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 146 | Requirement 8 Identify Users And Authenticate Access | Change history | CDE / firewall / payment flow | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 147 | Requirement 8 Identify Users And Authenticate Access | Risk exception | POS / store network / VPN | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 148 | Requirement 8 Identify Users And Authenticate Access | Monitoring signal | E-commerce / web / API | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 149 | Requirement 8 Identify Users And Authenticate Access | Alert response | Identity / server / endpoint | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 150 | Requirement 8 Identify Users And Authenticate Access | Vendor access | Logs / vendors / evidence | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 151 | Requirement 8 Identify Users And Authenticate Access | Administrative access | CDE / firewall / payment flow | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 152 | Requirement 8 Identify Users And Authenticate Access | Encryption status | POS / store network / VPN | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 153 | Requirement 8 Identify Users And Authenticate Access | Patch status | E-commerce / web / API | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 154 | Requirement 8 Identify Users And Authenticate Access | Vulnerability result | Identity / server / endpoint | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 155 | Requirement 8 Identify Users And Authenticate Access | Segmentation proof | Logs / vendors / evidence | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 156 | Requirement 8 Identify Users And Authenticate Access | Backup and recovery | CDE / firewall / payment flow | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 157 | Requirement 8 Identify Users And Authenticate Access | Incident response | POS / store network / VPN | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 158 | Requirement 8 Identify Users And Authenticate Access | Training or procedure | E-commerce / web / API | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 159 | Requirement 8 Identify Users And Authenticate Access | Management review | Identity / server / endpoint | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 160 | Requirement 8 Identify Users And Authenticate Access | Remediation ticket | Logs / vendors / evidence | Unique IDs, MFA, password policy, shared account review, admin access, and vendor authentication. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 161 | Requirement 9 Restrict Physical Access | Scope validation | CDE / firewall / payment flow | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 162 | Requirement 9 Restrict Physical Access | Evidence review | POS / store network / VPN | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 163 | Requirement 9 Restrict Physical Access | Configuration sample | E-commerce / web / API | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 164 | Requirement 9 Restrict Physical Access | Policy alignment | Identity / server / endpoint | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 165 | Requirement 9 Restrict Physical Access | Operational owner | Logs / vendors / evidence | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 166 | Requirement 9 Restrict Physical Access | Change history | CDE / firewall / payment flow | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 167 | Requirement 9 Restrict Physical Access | Risk exception | POS / store network / VPN | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 168 | Requirement 9 Restrict Physical Access | Monitoring signal | E-commerce / web / API | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 169 | Requirement 9 Restrict Physical Access | Alert response | Identity / server / endpoint | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 170 | Requirement 9 Restrict Physical Access | Vendor access | Logs / vendors / evidence | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 171 | Requirement 9 Restrict Physical Access | Administrative access | CDE / firewall / payment flow | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 172 | Requirement 9 Restrict Physical Access | Encryption status | POS / store network / VPN | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 173 | Requirement 9 Restrict Physical Access | Patch status | E-commerce / web / API | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 174 | Requirement 9 Restrict Physical Access | Vulnerability result | Identity / server / endpoint | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 175 | Requirement 9 Restrict Physical Access | Segmentation proof | Logs / vendors / evidence | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 176 | Requirement 9 Restrict Physical Access | Backup and recovery | CDE / firewall / payment flow | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 177 | Requirement 9 Restrict Physical Access | Incident response | POS / store network / VPN | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 178 | Requirement 9 Restrict Physical Access | Training or procedure | E-commerce / web / API | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 179 | Requirement 9 Restrict Physical Access | Management review | Identity / server / endpoint | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 180 | Requirement 9 Restrict Physical Access | Remediation ticket | Logs / vendors / evidence | Device security, media handling, visitor access, POS tampering checks, and facility procedures. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 181 | Requirement 10 Log And Monitor Access | Scope validation | CDE / firewall / payment flow | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 182 | Requirement 10 Log And Monitor Access | Evidence review | POS / store network / VPN | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 183 | Requirement 10 Log And Monitor Access | Configuration sample | E-commerce / web / API | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 184 | Requirement 10 Log And Monitor Access | Policy alignment | Identity / server / endpoint | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 185 | Requirement 10 Log And Monitor Access | Operational owner | Logs / vendors / evidence | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 186 | Requirement 10 Log And Monitor Access | Change history | CDE / firewall / payment flow | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 187 | Requirement 10 Log And Monitor Access | Risk exception | POS / store network / VPN | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 188 | Requirement 10 Log And Monitor Access | Monitoring signal | E-commerce / web / API | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 189 | Requirement 10 Log And Monitor Access | Alert response | Identity / server / endpoint | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 190 | Requirement 10 Log And Monitor Access | Vendor access | Logs / vendors / evidence | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 191 | Requirement 10 Log And Monitor Access | Administrative access | CDE / firewall / payment flow | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 192 | Requirement 10 Log And Monitor Access | Encryption status | POS / store network / VPN | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 193 | Requirement 10 Log And Monitor Access | Patch status | E-commerce / web / API | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 194 | Requirement 10 Log And Monitor Access | Vulnerability result | Identity / server / endpoint | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 195 | Requirement 10 Log And Monitor Access | Segmentation proof | Logs / vendors / evidence | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 196 | Requirement 10 Log And Monitor Access | Backup and recovery | CDE / firewall / payment flow | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 197 | Requirement 10 Log And Monitor Access | Incident response | POS / store network / VPN | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 198 | Requirement 10 Log And Monitor Access | Training or procedure | E-commerce / web / API | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 199 | Requirement 10 Log And Monitor Access | Management review | Identity / server / endpoint | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 200 | Requirement 10 Log And Monitor Access | Remediation ticket | Logs / vendors / evidence | Audit logs, SIEM, retention, alert review, time sync, privileged activity, and investigation evidence. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 201 | Requirement 11 Test Security Regularly | Scope validation | CDE / firewall / payment flow | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 202 | Requirement 11 Test Security Regularly | Evidence review | POS / store network / VPN | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 203 | Requirement 11 Test Security Regularly | Configuration sample | E-commerce / web / API | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 204 | Requirement 11 Test Security Regularly | Policy alignment | Identity / server / endpoint | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 205 | Requirement 11 Test Security Regularly | Operational owner | Logs / vendors / evidence | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 206 | Requirement 11 Test Security Regularly | Change history | CDE / firewall / payment flow | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 207 | Requirement 11 Test Security Regularly | Risk exception | POS / store network / VPN | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 208 | Requirement 11 Test Security Regularly | Monitoring signal | E-commerce / web / API | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 209 | Requirement 11 Test Security Regularly | Alert response | Identity / server / endpoint | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 210 | Requirement 11 Test Security Regularly | Vendor access | Logs / vendors / evidence | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 211 | Requirement 11 Test Security Regularly | Administrative access | CDE / firewall / payment flow | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 212 | Requirement 11 Test Security Regularly | Encryption status | POS / store network / VPN | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 213 | Requirement 11 Test Security Regularly | Patch status | E-commerce / web / API | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 214 | Requirement 11 Test Security Regularly | Vulnerability result | Identity / server / endpoint | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 215 | Requirement 11 Test Security Regularly | Segmentation proof | Logs / vendors / evidence | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 216 | Requirement 11 Test Security Regularly | Backup and recovery | CDE / firewall / payment flow | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 217 | Requirement 11 Test Security Regularly | Incident response | POS / store network / VPN | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 218 | Requirement 11 Test Security Regularly | Training or procedure | E-commerce / web / API | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 219 | Requirement 11 Test Security Regularly | Management review | Identity / server / endpoint | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 220 | Requirement 11 Test Security Regularly | Remediation ticket | Logs / vendors / evidence | Vulnerability scans, penetration tests, segmentation testing, wireless review, and change validation. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 221 | Requirement 12 Security Program Management | Scope validation | CDE / firewall / payment flow | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 222 | Requirement 12 Security Program Management | Evidence review | POS / store network / VPN | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 223 | Requirement 12 Security Program Management | Configuration sample | E-commerce / web / API | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 224 | Requirement 12 Security Program Management | Policy alignment | Identity / server / endpoint | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 225 | Requirement 12 Security Program Management | Operational owner | Logs / vendors / evidence | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 226 | Requirement 12 Security Program Management | Change history | CDE / firewall / payment flow | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 227 | Requirement 12 Security Program Management | Risk exception | POS / store network / VPN | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 228 | Requirement 12 Security Program Management | Monitoring signal | E-commerce / web / API | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 229 | Requirement 12 Security Program Management | Alert response | Identity / server / endpoint | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 230 | Requirement 12 Security Program Management | Vendor access | Logs / vendors / evidence | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 231 | Requirement 12 Security Program Management | Administrative access | CDE / firewall / payment flow | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 232 | Requirement 12 Security Program Management | Encryption status | POS / store network / VPN | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 233 | Requirement 12 Security Program Management | Patch status | E-commerce / web / API | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 234 | Requirement 12 Security Program Management | Vulnerability result | Identity / server / endpoint | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 235 | Requirement 12 Security Program Management | Segmentation proof | Logs / vendors / evidence | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Critical | Ready / Gap / Partial / N/A | P1 - Fix before audit |
| 236 | Requirement 12 Security Program Management | Backup and recovery | CDE / firewall / payment flow | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 237 | Requirement 12 Security Program Management | Incident response | POS / store network / VPN | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 238 | Requirement 12 Security Program Management | Training or procedure | E-commerce / web / API | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
| 239 | Requirement 12 Security Program Management | Management review | Identity / server / endpoint | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | High | Ready / Gap / Partial / N/A | P2 - Remediate soon |
| 240 | Requirement 12 Security Program Management | Remediation ticket | Logs / vendors / evidence | Policies, risk assessment, incident response, vendor management, training, and responsibility assignment. Collect screenshots, exports, diagrams, logs, tickets, or policy evidence tied to this control. | Medium | Ready / Gap / Partial / N/A | P3 - Track and document |
OC Security Audit identifies PCI DSS security gaps, risk, evidence needs, and audit-readiness priorities. When remediation requires ongoing IT implementation, network work, endpoint support, Microsoft 365/Azure administration, backup, monitoring, or managed IT follow-through, IT Perfection can support the related technical controls and operational implementation work.
For segmentation changes, firewall cleanup, switch/router support, and network infrastructure improvements.
For endpoint hardening, patching, server support, and system administration after technical findings.
For backup implementation, restore testing, disaster recovery planning, and continuity support.
For monitoring, patching, help desk, vendor coordination, and recurring maintenance after remediation planning.

Ali Hassani brings 25+ years of cybersecurity, IT infrastructure, network security, firewall security, vulnerability management, Microsoft infrastructure, compliance auditing, and executive risk experience to PCI DSS technical readiness work. His background helps organizations connect payment-system risk, technical controls, evidence, remediation, and business decisions.


It is a practical review of the systems, networks, applications, users, vendors, logs, vulnerabilities, and controls that support payment card processing and PCI DSS readiness.
No. It supports audit readiness by identifying technical gaps and evidence needs, but a formal PCI DSS audit or QSA engagement may still be required depending on your merchant level and obligations.
POS systems, payment applications, firewalls, VPNs, servers, e-commerce sites, cloud services, identity platforms, logging systems, vulnerability scanners, and vendor access paths are commonly reviewed.
Yes. Segmentation review, data-flow mapping, and payment architecture review can help identify opportunities to reduce unnecessary exposure and clarify the cardholder data environment.
Yes. The assessment can review payment-page flow, redirects, integrations, TLS, web server security, change control, scanning, and administrative access.
Yes. POS networks, remote support, segmentation, vendor access, logs, patching, firewall rules, and payment terminal exposure can be reviewed.
Useful evidence includes network diagrams, data-flow diagrams, firewall exports, access lists, vulnerability scans, patch records, logging screenshots, vendor records, policies, and remediation tickets.
Yes. OC Security Audit can coordinate with internal IT, vendors, MSPs, payment processors, e-commerce teams, and leadership to clarify findings and remediation priorities.
The assessment can review vulnerability scan results and remediation tracking. If scanning is needed, scope and timing should be planned carefully to avoid disrupting payment systems.
Deliverables may include an executive summary, technical findings, evidence checklist, risk ratings, scope observations, and a prioritized remediation roadmap.
Payment security controls should be reviewed at least annually and whenever major changes occur, such as new POS systems, firewall changes, e-commerce redesigns, cloud migrations, or vendor changes.
Yes. Preparing evidence before an audit helps reduce confusion, clarify responsibility, and give IT teams time to remediate findings.
Yes. OC Security Audit supports businesses in Irvine, Orange County, Los Angeles County, and Southern California with PCI DSS readiness and technical security assessment services.
OC Security Audit reviews your payment environment, confirms scope, explains likely evidence needs, and recommends a practical assessment plan.
OC Security Audit can guide remediation priorities and validation. When implementation or managed IT work is needed, related operational support may be handled through IT Perfection where appropriate.
The assessment is planned to minimize disruption. Any testing or scanning that could affect production systems should be scheduled and scoped carefully.
Yes. Vendor remote access, MFA, shared accounts, VPN access, support tools, logging, and least-privilege permissions are important PCI DSS review areas.
Yes. The assessment can align findings and evidence planning with PCI DSS 4.0 readiness, including security control validation, documentation, and remediation tracking.
Review PCI DSS scope, firewall rules, segmentation, POS systems, e-commerce payment flow, access control, logs, vulnerability management, vendor access, and technical evidence readiness.
This audit page should connect technical assessment work to the broader PCI DSS campaign: scope, 12 requirements, SAQ/AOC/ROC expectations, evidence, testing, and implementation support.
Move through the PCI DSS review in a practical order: understand the payment environment, define scope, map controls to evidence, validate testing requirements, and turn findings into remediation work for the business, IT team, MSP, and payment vendors.

If the team is still defining the payment environment, review What Is PCI DSS? and Who Needs PCI DSS Compliance?. These pages explain cardholder data, service-provider impact, merchants, ecommerce, POS, and vendor responsibility.
Use PCI DSS Requirements Explained and PCI DSS Scope and Segmentation to connect the 12 control areas to firewalls, secure configuration, account data protection, access control, logging, testing, and policy evidence.
When the business is preparing an SAQ, AOC, ROC, QSA conversation, or ASV scan, continue with PCI DSS Validation Guide and PCI DSS Evidence Checklist.
For technical gaps, review Vulnerability Scanning and Penetration Testing, Cloud, Ecommerce, POS, and Payment Applications, and the PCI DSS Compliance Roadmap. For guided help, contact OC Security Audit.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.