Network Trace
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

06) Has your organisation performed validation of compliance to the Payment Card Industry Data Security Standard (PCI DSS) v4 or above for your services or environments that impact cardholder data or sensitive authentication data?

Security Certifications
Other
SOC2
Small Framework

Answer yes if your organisation’s relevant services or environments have been validated through either: (1) a Self Assessment Questionnaire (SAQ), or (2) a Report on Compliance (RoC) if performed by a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA). Upload the Attestation of Compliance (AOC) and the Shared Responsibility Matrix.

PCI DSS v4.0 is the current global standard designed to ensure that organisations that process, store, or transmit credit card information maintain a secure environment. Validation is typically via a Self-Assessment Questionnaire (SAQ), or for larger organisations or those with higher transaction volumes, a more rigorous Report on Compliance (RoC) is required, conducted by either an ISA or a QSA. Regardless of the assessment type, an Attestation of Compliance (AoC) is used to demonstrate your compliance. Please provide the AoC and associated the Shared Responsibility Matrix.

How to implement the control

Please visit the PCI Security Standards Council’s website for more information on whether your organisation may need to comply with the PCI DSS.

If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.

Pattern Trapezoid Mesh

Defend against supply chain attacks with Defend-As-One.

No organisation is an island.