PCI Requirements - You're Not Done Yet!

PCI compliance isn’t an event. It’s an ongoing process!

PCI
Security Tools
PCI Requirements - You're Not Done Yet!

Compliance is a day-by-day security process.

PCI compliance isn’t an event. It’s an ongoing process! Lots of people believe they can ‘finish’ or ‘complete’ PCI requirements, but it doesn’t really work like that. A submitted Self-Assessment Questionnaire (SAQ) is only as good as the proactive, ongoing security of the business behind it.

I think Bob Russo, head of the PCI Security Standards Council said it best.

“Organizations must not take solely a checklist approach to security, or rely on periodic validation on a specific day as their security goal, but must instead exercise continuous vigilance and maintain a strict security program that ensures constant and ongoing PCI DSS compliance."

Watch the video to learn the best ways to maintain your hard-earned compliance.

Want to see more vids like this? Subscribe on YouTube for PCI security tips.

So let’s recap.

How exactly are you supposed to maintain PCI requirements?

  • Ensure your security policies are updated. Anytime you change the way you store, process, or transmit cardholder data, update those policies to reflect the changes!
  • Train your employees. While training new (and current) staff members, remind them about the rights and wrongs of correct card data handling.
  • Update your SAQ if things change. If anything in your card processing environment changes, your SAQ is no longer valid! Update and resubmit your SAQ for best results.
  • Run external vulnerability scans. If your business is required to scan for vulnerabilities, make sure scans run at least quarterly and when you make any network changes. (Do you see a pattern yet?)
  • Understand where your credit card data is stored. One of the reasons it’s hard to maintain compliance is because businesses accidentally store unencrypted card data. Identify unencrypted card data with card discovery tools like PANscan®.

Join Thousands of Security Professionals.

Subscribe Now

Get the Guide To PCI Compliance

Download

Get Quote for PCI Compliance

Request a Quote