PCI DSS Guru
Payment Card Industry Data Security Standard

                   
  • Home
  • Forum

Sample PCI-DSS Policy Part 1: Introduction

Introduction

Note: This sample is meant to demonstrate how the PCI-DSS might be employed directly to generate a policy. It would require significant adaptation to be deployed successfully in an actual card processing environment. Individual requirements from the PCI-DSS are denoted in parentheses.

Issue Date: xx/xx/xxxx
Reviewed: xx/xx/xxxx

Policy Statement

(12.1.1) All card processing activities and related technologies must comply with the Payment Card Industry Data Security Standard (PCI-DSS) in its entirety. Card processing activities must be conducted as described herein and in accordance with the standards and procedures listed in the Related Documents section of this Policy. No activity may be conducted nor any technology employed that might obstruct compliance with any portion of the PCI-DSS.

(12.1.3) This policy shall be reviewed at least annually and updated as needed to reflect changes to business objectives or the risk environment.

Applicability and Availability

This policy applies to all employees. (12.1) Relevant sections of this policy apply to vendors, contractors, and business partners. The most current version of this policy is available (at X URL or through Y office).

Policy Requirements

  • Adherence to Standards

  • Handling of Cardholder Data

  • Access to Cardholder Data

  • Critical Employee-facing Technologies

  • Roles and Responsibilities

  • Related Documents

    • Standards
    • Incident Response Plan
    • Procedures

Posted in Policy |

3 Responses

  1. sunny

    July 9th, 2009 at 1:42 am

    Do we need to quote the relevant standard/section number in the policy

  2. admin

    July 16th, 2009 at 7:52 pm

    The standard doesn’t require it. However, it’s probably a good idea to do so in the draft version so that you can check off each requirement. The version you publish/promote to your company can be stripped of the references, for readability.

    The standard is ever evolving, so keep that draft version around to cross reference and fill any gaps that appear as a result of the changes!

  3. Daniel de Jager

    October 26th, 2009 at 4:34 am

    Would the above be an outline to the actual document?

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.

Search Posts


Categories

  • Application Firewalls
  • Code Review
  • Encryption
  • PCI DSS
  • Penetration Testing
  • Policy
Copyright 2007, Plainfacts.net