PCI Controls - Tips and Tricks

A list of suggested updates that will need to be made to the control library for PCI controls

Written By Micah

When using Strike Graph to manage your controls and adding on the PCI framework, we recommend making a few updates to the control language to cover additional requirements. You can use the guidance below to make these changes to the controls within your Control Library and to activate additional controls that may be relevant to your organization.

Remember, you can and should edit the control descriptions to ensure that they accurately describe your processes.

  • Asset Inventory

    Add the following to the end of the existing control description: Assets relevant to PCI compliance are identified. This should include remote access and wireless technologies, and removable media. All PCI-relevant assets should include owner, contact information, and purpose.

  • Badge Access System

  • Add the following to the end of the existing control description: Badge access logs are maintained for 90 days and monitored periodically.

  • Firewall Rule Review

    Replace the existing control description with the following: Firewall rules and router rule sets are reviewed every 6 months, and are formally documented. You can leave the Control Frequency as Annually, but be sure to update the evidence expiration to 180 days.

  • Incident Response: Responsibility

    Add the following to the end of the existing control description: An incident response test is completed annually.

  • Pen Test

    Update the control description to include web app testing.

  • Role Based Access

    Add the following to the end of the existing control description: Roles and their permissions are defined for users in the organization.

  • Secure Coding

    Add the following to the end of the existing control description: This includes industry standard vulnerability scanning for all internal and external applications to address common coding vulnerabilities.

  • Visitor Sign-in

    Add the following to the end of the existing control description: The log captures the name, firm/organization, who is visiting/authorizing, and the date of the visit. The log is retained for at least 90 days. Logs are reviewed each month.

  • Vulnerability Scan

    Add the following to the end of the existing control description: High, Critical, or Urgent patches are deployed within 30 days.