PCI Controls - Tips and Tricks
A list of suggested updates that will need to be made to the control library for PCI controls
Written By Micah
When using Strike Graph to manage your controls and adding on the PCI framework, we recommend making a few updates to the control language to cover additional requirements. You can use the guidance below to make these changes to the controls within your Control Library and to activate additional controls that may be relevant to your organization.
Remember, you can and should edit the control descriptions to ensure that they accurately describe your processes.
Asset Inventory
Add the following to the end of the existing control description: Assets relevant to PCI compliance are identified. This should include remote access and wireless technologies, and removable media. All PCI-relevant assets should include owner, contact information, and purpose.
Badge Access System
Add the following to the end of the existing control description: Badge access logs are maintained for 90 days and monitored periodically.
Firewall Rule Review
Replace the existing control description with the following: Firewall rules and router rule sets are reviewed every 6 months, and are formally documented. You can leave the Control Frequency as Annually, but be sure to update the evidence expiration to 180 days.
Incident Response: Responsibility
Add the following to the end of the existing control description: An incident response test is completed annually.
Pen Test
Update the control description to include web app testing.
Role Based Access
Add the following to the end of the existing control description: Roles and their permissions are defined for users in the organization.
Secure Coding
Add the following to the end of the existing control description: This includes industry standard vulnerability scanning for all internal and external applications to address common coding vulnerabilities.
Visitor Sign-in
Add the following to the end of the existing control description: The log captures the name, firm/organization, who is visiting/authorizing, and the date of the visit. The log is retained for at least 90 days. Logs are reviewed each month.
Vulnerability Scan
Add the following to the end of the existing control description: High, Critical, or Urgent patches are deployed within 30 days.