Talk With an Expert

Project Management Approach to Yearly PCI Compliance Assessment

Project Management Approach to Yearly PCI Compliance Assessment (PDF, 2.64MB)Published: 19 Feb, 2013
Created by
Michael Hoehl

The Payment Card Industry (PCI) Data Security Standard (DSS) provides a list of over 200 controls that must be inspected yearly by organizations handling credit card data. As several organizations have learned, contracting a QSA to perform a PCI DSS yearly validation is simply not enough to ensure success. A comprehensive, repeatable approach is required to perform the yearly inspection in a uniform and credible manner. This paper provides guidance to prepare for and conduct the PCI yearly validation using project management methodology. Several lessons learned are included so the PCI validation project ends with a success storyó-not a post-mortem.