Knowing all the locations, where you both physically operate from and also where all elements of the processing, storage and transmission of card holder data is within your environment is critical. Mapping the data flow paths through your systems and networks is an essential step in knowing the starting point for the work.
What are the key technologies in play within your networks and systems? What versions and types of equipment are in place and where do they reside? Who are the vendors?
- Completion of a hardware asset inventory.
- Completion of a software asset inventory.
Who is involved? Not just from an operational end users perspective but also administrators, support functions – both internal and external.
- Completion of Responsibility, Accountability, Consulted, Informed (RACI) matrix.
How many payment channels are there and how and where are they facilitated? Are any isolated from each other or do they rely on common or shared infrastructure? What Self-Assessment Questionnaires (SAQs) apply?
What are the applicable controls that need to be applied to the identified payment channels? What control responsibility has been outsourced to an external organisation?
What services, supporting the organisation’s payment channels have been outsourced? What legal contracts do we have in place, to ensure that they are delivering a compliant service? What type of due diligence is needed to ensure that they can meet the requirements of the contract? How can the compliancy of the outsourced services be effectively managed?
- Completion of a responsibilities matrix.
Mapping your data flows is key. Not only the flows of card holder data but also the administration access, communication links, 3rd party access and any user access.
Where and what policies and procedures are in place? Where are they located? Who owns them and how are they maintained? Are they understood? Are they effective?
- Completion of document catalogue.
- Completion of policy tree.
- What is the target date for compliance? What are the key milestones, against the 7 stages? Complete the schedules matrix.