PCI DSS v4.0
16 of the 249 clauses of PCI DSS v4.0 are cited by this register, on Asset inventory sync, Audit evidence pack export, Audit log retention and archive, Breach notification report pack, Card environment log review, Compliance attestation and scope confirmation, Credential and password rotation, File integrity and change detection and more. Every one below is quoted from the copy we hold, with the hours it states where it states any.
File integrity monitoring or change-detection mechanisms are used on audit logs to ensure that existing log data cannot be changed without generating alerts.
What an assessor asks to see: FIM tool configuration covering log paths; Sample FIM alerts on log modification tests; Coverage list across systems; Procedure for FIM alert triage. Where it usually falls short: FIM not deployed on logs
The following audit logs are reviewed at least daily: all security events, logs of all CDE system components, logs of critical systems, and logs of authentication, authorization, and accounting services.
What an assessor asks to see: SIEM dashboard showing daily review sign-off; Documented use cases reviewed daily; Triage tickets from daily reviews; Reviewer assignment and rotation. Where it usually falls short: Reviews skipped on weekends
Automated mechanisms are used to perform audit log reviews.
What an assessor asks to see: SIEM correlation rules export; UEBA or analytics tool configuration; Sample alerts and triage; Tuning records reducing false positives. Where it usually falls short: Manual-only review
Logs of all other system components (those not specified in 10.4.1) are reviewed periodically.
What an assessor asks to see: Review schedule for non-critical systems; Sample of completed reviews; Sign-off records by reviewer; Inventory of systems in scope. Where it usually falls short: Reviews not performed
The frequency of periodic reviews for all other system components is defined in the entity's targeted risk analysis.
What an assessor asks to see: TRA document with risk inputs and chosen cadence; Annual TRA review records; Approval by senior leadership; Mapping of cadence to system criticality. Where it usually falls short: No TRA
Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.
What an assessor asks to see: SIEM retention policy configuration; Hot storage configuration for last 3 months; Cold storage location and accessibility evidence; Sample log restoration test results. Where it usually falls short: Retention below 12 months
Failures of critical security control systems are detected, alerted, and addressed promptly for all entities (not just service providers), with documented response procedures.
What an assessor asks to see: Documented list of critical security controls; Health monitoring configuration per control; Alert routing to on-call; Sample failure tickets with response evidence. Where it usually falls short: List of critical controls missing
Internal vulnerability scans are performed at least once every three months, with high-risk and critical vulnerabilities resolved per the entity's risk ranking, and re-scans confirm resolution.
What an assessor asks to see: Quarterly scan reports for past 12 months; Risk ranking documentation; Remediation tickets with closure; Re-scan reports confirming fix. Where it usually falls short: Coverage incomplete
External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV) with passing scans achieved.
What an assessor asks to see: ASV scan reports for past 4 quarters (passing); ASV attestation of scan compliance; Remediation tickets for failed scans; Re-scan reports confirming pass. Where it usually falls short: No passing scan
An incident response plan exists and is ready to be activated in the event of a suspected or confirmed security incident, covering roles, responsibilities, communication, containment, and recovery.
What an assessor asks to see: Incident response plan with named roles; Communication trees including legal, comms, law enforcement; Containment and recovery procedures; Approval and version control. Where it usually falls short: IRP stale
The incident response plan is reviewed at least once every 12 months and updated as needed, and tested annually.
What an assessor asks to see: Annual IRP review minutes; Tabletop exercise reports; Lessons learned and IRP updates; Participant lists for exercises. Where it usually falls short: No annual test
PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.
What an assessor asks to see: Scope document with named components; Data flow diagrams covering all CHD flows; Network and segmentation diagrams; Annual scoping exercise minutes and sign-off. Where it usually falls short: Diagrams stale
All system components are protected from known vulnerabilities by installing applicable security patches/updates as follows: • Patches/updates for critical vulnerabilities (identified according to the risk ranking process at Requirement 6.3.1) are installed within one
What an assessor asks to see: Risk appetite statement; Risk tolerance thresholds; Impact and likelihood scales. Where it usually falls short: Criteria not approved by leadership
All user accounts and related access privileges, including third-party/vendor accounts, are reviewed as follows: • At least once every six months. • To ensure user accounts and access remain appropriate based on job function.
What an assessor asks to see: Auditable consent records with timestamp, version, and channel. Where it usually falls short: Consent capture mechanism does not record purpose, time, and version of notice shown
If passwords are the only authentication factor, they are changed at least every 90 days, or access to resources is dynamically analyzed and access granted based on security posture.
What an assessor asks to see: Password expiration policy set to 90 days where applicable; Dynamic access posture tool configuration if used; Coverage matrix of password-only systems; Sample of forced password changes. Where it usually falls short: Expiration disabled with no compensating control
Offline media backups containing cardholder data are stored in a secure location, with security reviewed at least once every 12 months.
What an assessor asks to see: Offsite vendor agreement and SOC report; Annual site security review evidence; Inventory of backup media offsite; Chain of custody records for media transfers. Where it usually falls short: Annual review skipped
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.