PCI Risk Assessment Policy and Procedures Template

Written By Micah

PCI DSS 12.2.1 requires that a risk assessment be performed. The risk assessment must consider the risks to cardholder data (CHD) as well as the cardholder data environment (CDE). The process includes identification of the organization’s assets, as well as the threats and vulnerabilities that apply; assessment of the likelihood and impact (risk) of the threats and vulnerabilities being realized, identification of treatment for each unacceptable risk, and evaluation of the residual risk after treatment.

Commonly associated evidence:

  • Risk Assessment Procedures

  • Risk Assessment

Who needs a policy like this?

  • Businesses that need to conform to PCI requirements.

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

Questions?

Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.