PCI DSS Requirements and Audit Procedures
A comprehensive overview of PCI DSS requirements and practical audit procedures for IT auditors assessing cardholder data environments.
The Payment Card Industry Data Security Standard (PCI DSS) establishes security requirements for organizations that store, process, or transmit cardholder data. IT auditors assessing PCI DSS compliance need to understand the standard's 12 requirements, the concept of the cardholder data environment (CDE), and the practical procedures for evaluating compliance.
PCI DSS Structure
PCI DSS version 4.0 organizes its requirements into six goals with 12 principal requirements. Each requirement contains detailed sub-requirements with defined testing procedures and guidance.
Goal 1: Build and Maintain a Secure Network and Systems
- Requirement 1: Install and maintain network security controls. Review firewall and router configurations, network segmentation, and rules governing traffic to and from the CDE.
- Requirement 2: Apply secure configurations to all system components. Verify that vendor-supplied defaults are changed, unnecessary services are disabled, and hardening standards are applied consistently.
Goal 2: Protect Account Data
- Requirement 3: Protect stored account data. Verify data retention policies, assess encryption and masking of stored cardholder data, and confirm that sensitive authentication data is not stored after authorization.
- Requirement 4: Protect cardholder data with strong cryptography during transmission over open, public networks. Review encryption protocols, certificate management, and network transmission security.
Goal 3: Maintain a Vulnerability Management Program
- Requirement 5: Protect all systems and networks from malicious software. Assess anti-malware deployment, update mechanisms, and coverage across all system types in the CDE.
- Requirement 6: Develop and maintain secure systems and software. Review secure development practices, patch management processes, and web application security controls.
Goal 4: Implement Strong Access Control Measures
- Requirement 7: Restrict access to system components and cardholder data by business need to know. Evaluate role-based access control implementation and access approval processes.
- Requirement 8: Identify users and authenticate access to system components. Review authentication mechanisms, password policies, and multi-factor authentication implementation.
- Requirement 9: Restrict physical access to cardholder data. Assess physical security controls for facilities housing CDE components.
Goal 5: Regularly Monitor and Test Networks
- Requirement 10: Log and monitor all access to system components and cardholder data. Verify audit logging configuration, log review processes, and time synchronization.
- Requirement 11: Test security of systems and networks regularly. Review vulnerability scanning results, penetration testing reports, and intrusion detection capabilities.
Goal 6: Maintain an Information Security Policy
- Requirement 12: Support information security with organizational policies and programs. Assess the information security policy, risk assessment process, security awareness training, and incident response plan.
Scoping the CDE
Accurate scoping is critical for PCI DSS assessments. The CDE includes all system components that store, process, or transmit cardholder data, plus any component connected to or that could impact the CDE's security. Network segmentation can reduce scope but must be validated through penetration testing.
Audit Procedures
- Begin with scoping validation to confirm the boundaries of the CDE
- Review network diagrams and data flow documentation
- Interview personnel responsible for security controls
- Inspect system configurations and security settings
- Test a sample of controls for operating effectiveness
- Review compensating controls documentation where applicable
- Document all findings with specific requirement references
Common Findings
Frequent issues include incomplete CDE scoping, inadequate network segmentation, inconsistent system hardening, gaps in log monitoring, delayed patching, and insufficient access reviews. Understanding these common pitfalls helps auditors focus their testing efficiently.
PCI DSS expertise is highly valued in the IT audit profession. CISA professionals who develop proficiency in payment card security assessment are well positioned for roles in financial services, retail, and payment processing organizations.