RSI Security

What’s in a PCI Level 4 Self-Assessment?

MSSp

A company’s cybersecurity infrastructure must often meet industry-specific regulatory compliance requirements. While many compliance frameworks apply only to specific sectors, some span broader cross-sections of the market at large. For example, the Payment Card Industry (PCI) framework applies,THE SECURITY STANDARDS COUNCIL (SSC) PRESIDED OVER the to all companies that process, store, or transmit credit card data. Reporting efforts are determined by yearly transaction volume, and those below 20,000 per year must submit annual answers to PCI compliance Level 4 self-assessment questions.

 

What’s in a PCI Level 4 Self-Assessment?

Understanding what it takes to complete a Self-Assessment Questionnaire (SAQ) for PCI compliance Level 4 first requires knowing the category and control schema. Then, you can sink your teeth into the different documents that might be necessary. You’ll want to familiarize yourself with:

 

What is PCI Self-Assessment? Do You Need it?

The SAQ is a critical part of the overall PCI compliance process, required for all companies that process, store, or transmit credit card data.

Companies at Level 4 (i.e., handling 20,000 transactions or fewer per year) only have to self-assess, whereas higher levels need to do so and provide additional documents. However, all PCI-bound companies must submit a self-assessment to avoid penalties regardless of their Level.

Failure to comply with PCI regulations may result in serious short- and long-term consequences. For example, if your company suffers a cybersecurity breach and customers’ cardholder data is compromised, it may be charged $50 to $90 per affected individual. For passive non-compliance, you may be charged escalating monthly fines:

Put simply you need to submit your yearly SAQ because non-compliance is expensive.

 

PCI DSS Framework and Requirements

Before digging into the PCI DSS self-assessment process, it’s critical to understand the framework itself and the context surrounding its requirements. The DSS exists to protect the cardholder data (CHD) of credit and debit users. These protections cover CHD stored, processed, transmitted, and otherwise utilized across all business operations.

The DSS and all other PCI standards are presided over by the Security Standards Council (SSC), which comprises five founding members and other stakeholders. The Founding Members are Visa, Mastercard, American Express, JCB International, and Discover. Strategic Members like Union Pay and the Board of Advisors—comprising representatives from Amazon, Google, and other industry leaders—also contribute to PCI oversight.

Ultimately, self-assessment measures your company’s implementation of the PCI DSS’s requirements and controls. Understanding the SAQ requires knowing what the DSS comprises.

 

Request a Free Consultation

 

What PCI Controls Do You Need to Implement?

The PCI DSS is currently in version 3.2.1, current as of May 2018. The DSS’s core comprises six “Goals” for cardholder data security that break down into 12 “Requirements.” These are:

These requirements have remained essentially unchanged since the original publication of version 1.1 in 2006. Version 4.0 is expected to release soon with few projected changes.

Different Levels of PCI DSS Compliance

Concerning the framework detailed above, all companies need to implement all Requirements, regardless of their Level, along with the controls specified for each. Requirements break down into sub-requirements, denoted by additional decimal points. These do not relate at all to PCI Levels, which are determined exclusively by yearly transaction volume.

For example, “Requirement 1” from above appears as “1.0” in the DSS, and it is followed by several sub-requirements (“1.1,” “1.2,” etc.). Each of these then breaks down into Testing Procedures (“1.1.a,” “1.1.b,” etc.), which provide specific metrics companies may use to evaluate their implementation. Specific guidance also accompanies most sub-requirements.

Where there is one difference in PCI Levels is regarding compliance reporting. Companies with the fewest transactions overall need to submit only an SAQ, whereas those with higher volumes need an Attestation of Compliance (AOC), Report on Compliance (ROC), or both.

 

What Are the Levels for PCI DSS Reporting?

The Founding Members of the PCI SSC are responsible for enforcing the DSS and other PCI frameworks. They also determine what companies must do to comply and what penalties they face for non-compliance. According to Visa’s PCI DSS guidance, there are four PCI DSS levels:

Critically, these levels scale-up in reverse order, with 4 being the lowest and 1 being the highest in terms of required documentation. With 3 and 2 bearing identical requirements, the biggest leaps are from 4 to 3 (just SAQ to SAQ and AOC) and 2 to 1 (all three: SAQ, AOC, and ROC).

 

QSAs and ASVs—SSC-Approved Third-Parties

The PCI SSC requires third parties that have received their approval to complete AOCs and ROCs. Approved third parties, including RSI Security, are called Qualified Security Assessors (QSA) and Approved Scanning Vendors (ASV). Though Level 4 doesn’t require third-party involvement, you will need to contact one if your transaction volume increases beyond 20,000 per year.

PCI Self-Assessment Questionnaire (SAQ)

Reporting on PCI compliance for companies at Level 4 can be done entirely in-house. However, many companies still benefit from outside assistance during implementation and assessment. Nonetheless, the PCI DSS SAQ is a relatively straightforward document, beginning with a basic survey about company facts. The second section asks questions about each DSS Requirement and sub-requirement. Requirement questions are answered with one of the following:

The end of the SAQ contains appendices for additional information, such as Compensating Control Worksheets (CCWs) and for providing explanations of all “N/A” answers. There is also a section titled “Action Plan for Non-Compliant Requirements,” where companies may indicate remediation efforts and their expected completion date for all “No” answers.

One note: Since PCI compliance Level 4 reporting requires only the SAQ and not an AOC or ROC, this guide will focus on the former rather than the latter two.

 

How Many PCI DSS SAQ Variants Are There?

Another critical consideration about the PCI DSS SAQ is that there are many form variations, each of which applies to different companies depending on their business activity. There are eight primary SAQ variants:

A guide to understanding the SAQ variants is freely available via the SSC document library, along with all other pertinent PCI SSC texts, pending acceptance of terms and conditions.

 

Other PCI Compliance Level 4 Considerations

As detailed above, the process of filling out the SAQ is relatively straightforward. The most considerable challenges lie in implementing all required controls and selecting the appropriate SAQ. Some companies may also face challenges in mapping controls between additional compliance frameworks they implement simultaneously. PCI DSS is flexible, as companies can utilize compensating controls in some cases, but other compliance frameworks may be less so.

Beyond the initial implementation of these controls, other challenges companies may face involving the long-term maintenance thereof. An SAQ and other documents must be submitted annually, but a PCI SSC audit can happen at any time, so compliance must be upheld year-round. A robust PCI compliance advisory suite should include comprehensive patch reporting and maintenance.

 

What is Payment Application DSS Compliance?

Yet another challenge companies may face in achieving and maintaining PCI DSS compliance is balancing the 12 Requirements with other controls required by other PCI frameworks. One widely-applicable example is the Payment Application (PA) DSS, which applies to app makers and users. Its Requirements are relatively similar to those of the DSS, comprising 14 in total:

Critically, companies need to track all data pertinent to these requirements separately from their DSS documentation. There are different reporting protocols for these (and all other) frameworks.

 

Achieve and Maintain PCI DSS Compliance

Completing your PCI compliance level 4 self-assessment involves first implementing all controls required for DSS adherence and then answering the questions on the SAQ version that fits your business type.

If your company is on the cusp of moving into Level 3 or beyond, it will also need to prepare more thorough documentation. RSI Security will assist in all compliance elements, from assessment through patch management and mapping to other frameworks.

To see how streamlined and powerful your compliance process can be, contact RSI Security today!

 

 

Exit mobile version