PCI Risk Assessment Policy and Procedures Template
Written By Micah
PCI DSS 12.2.1 requires that a risk assessment be performed. The risk assessment must consider the risks to cardholder data (CHD) as well as the cardholder data environment (CDE). The process includes identification of the organization’s assets, as well as the threats and vulnerabilities that apply; assessment of the likelihood and impact (risk) of the threats and vulnerabilities being realized, identification of treatment for each unacceptable risk, and evaluation of the residual risk after treatment.
Commonly associated evidence:
Risk Assessment Procedures
Risk Assessment
Who needs a policy like this?
Businesses that need to conform to PCI requirements.
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.