Skip to content

PCI-DSS v4.0

Achieve PCI-DSS compliance for payment card processing with CyberOrigen.

Overview

PCI-DSS (Payment Card Industry Data Security Standard) is required for any organization that stores, processes, or transmits cardholder data.

Requirements

12 Requirements

#Requirement
1Install and maintain network security controls
2Apply secure configurations
3Protect stored account data
4Protect cardholder data with strong cryptography
5Protect systems against malware
6Develop and maintain secure systems
7Restrict access by business need-to-know
8Identify users and authenticate access
9Restrict physical access to cardholder data
10Log and monitor all access
11Test security regularly
12Support security with policies and programs

Validation Levels

LevelCriteriaValidation
1>6M transactions/yearAnnual ROC by QSA
21-6M transactions/yearAnnual SAQ, quarterly ASV
320K-1M e-commerceAnnual SAQ, quarterly ASV
4<20K e-commerce or <1M otherAnnual SAQ, quarterly ASV

Getting Started

1. Enable Framework

  1. Go to GRCFrameworks
  2. Click Enroll on PCI-DSS v4.0
  3. Select applicable SAQ type
  4. Click Enable

2. Scope Definition

Define your Cardholder Data Environment (CDE):

  • Systems that store/process/transmit CHD
  • Connected systems
  • Security systems

3. Gap Assessment

  1. Run compliance scan
  2. Review requirements
  3. Identify gaps
  4. Plan remediation

Key Requirements

Requirement 6 - Secure Development

Sub-ReqTitleCyberOrigen Feature
6.2Vulnerability identificationVulnerability scanning
6.3Secure developmentSAST with Semgrep
6.4Web application securityWeb app scanning
6.5Change managementChange tracking

Requirement 11 - Security Testing

Sub-ReqTitleCyberOrigen Feature
11.2Vulnerability scansQuarterly scanning
11.3Penetration testingScan reports
11.4Intrusion detectionThreat intelligence

Scanning Requirements

Internal Scanning

Requirement 11.2.1: Quarterly internal vulnerability scans.

CyberOrigen provides:

  • Automated scheduling
  • Compliance-mapped findings
  • Remediation tracking
  • Trend reporting

External Scanning

Requirement 11.2.2: Quarterly external scans by ASV.

CyberOrigen scans meet PCI requirements:

  • External perspective
  • Full port scanning
  • SSL/TLS analysis
  • Compliance reporting

Penetration Testing

Requirement 11.3: Annual penetration testing.

CyberOrigen supports:

  • Scan-based assessment
  • Finding documentation
  • Remediation verification

Control Mapping

CyberOrigen maps PCI-DSS to other frameworks:

PCI-DSSSOC 2ISO 27001
1.1CC6.6A.8.20
2.1CC6.1A.8.9
3.4CC6.7A.8.24
6.1CC7.1A.8.8
7.1CC6.1A.5.15
8.1CC6.1A.5.16
10.1CC7.2A.8.15
11.2CC7.1A.8.8

Evidence Collection

Automated Evidence

  • Vulnerability scan reports
  • Configuration assessments
  • Access reviews
  • Network topology

Manual Evidence

  • Policies and procedures
  • Data flow diagrams
  • Incident response plans
  • Training records

SAQ Types

SAQ A

E-commerce, all cardholder data outsourced:

  • Minimal requirements
  • Mainly policies and vendor management

SAQ A-EP

E-commerce with partial outsourcing:

  • Web application requirements
  • Redirect security

SAQ D

Full assessment for service providers or merchants:

  • All 12 requirements
  • Complete documentation

Quarterly Activities

  • Internal vulnerability scan
  • External vulnerability scan (ASV)
  • File integrity monitoring review
  • User access review
  • Wireless network scan

Annual Activities

  • Penetration test
  • Policy review
  • Security awareness training
  • Incident response testing
  • Risk assessment

Common Gaps

RequirementIssueSolution
2.1Default passwordsPassword policy
3.4Unencrypted PANEncryption implementation
6.2Unpatched systemsPatch management
8.3No MFAMFA deployment
11.2Missing scansScan scheduling

Resources

Agentic AI-Powered Security & Compliance