PCI Mandatory Documents
1 min readJul 27, 2018
List of all documents that we have to prepare based on PCI DSS 3.2.1:
- Security policy
- Risk assessment and risk analysis process
- Diagram or a documented inventory of cardholder data locations
- Up-to-date list of devices and system components that are in scope for PCI DSS
- Current network diagram that identifies all connections between the CDE and other networks
- Current data-flow diagram that shows all cardholder data flows across systems and networks
- List of services, protocols and ports that that are necessary for business
- Configuration standards (system hardening standards) for all system components in PCI scope
- Data retention and disposal policies and procedures including processes for secure deletion of data when no longer needed
- Business recovery and continuity procedures and data backup processes
- Documented process for testing and approval of changes to firewall and router configurations
- Description of roles and assignment of responsibilities about security of network devices
- Procedures to manage and protect keys used to secure stored cardholder data
- Authentication policies and procedures
- Processes to test for the presence of wireless access points
- Incident response procedures in the event unauthorized wireless access points are detected
- A process to respond to any alerts generated by the change-detection solution (like FIM)
- Usage policies for critical technologies and define proper use of these technologies
- Incident response plan