Have you almost quit your PCI Compliance job after submitting your organization’s Report on Compliance?

Don’t be shy. It’s okay if you walked away.

I almost quit I submitted the first PCI Report on Compliance I ever worked on.

But…

I didn’t quit. 

I didn’t walk away.

Instead, I saw the opportunity to build a world class PCI DSS Compliance program.

Over the course of my 10 years managing a complex continuous PCI Compliance program at a level 1 merchant, I created a laundry list of do’s and don’ts. 

I captured a lot of up front work that must be done *before* you start your PCI Report on Compliance.

Understanding your scope before you begin assessing is critical to the success of your Report on compliance. That upfront work must be done before you start the RoC.

I don’t believe in reinventing the wheel with every assessment so I created a Report on Compliance Planner as well as a Consolidated Interview and Observation Schedule.

Why? There are so many moving parts during a Report on Compliance. Without

  • repeatable processes
  • clear milestones
  • a communication’s plan
  • an escalation path
  • and who does what directory

All you’ll have is a big ball of goo.

And that’s no fun.

I’m also lazy.

The more efficiently I can work, the more time I have to play word games…I mean work on process improvement.

Together with Lisa Cressey, we automated critical controls so that we could self-collect the evidence and not depend on squirrely system administrators.

We also automated the entire Report on Compliance assessment process

Yes.

We did.

Why?

Because there were only two of us running a PCI Compliance program at a Fortune 100 Company and Level 1 merchant.

It was nerve wrecking to say the least.

Now…

Keep reading (and watch the video at the end) because I’ve got 5 actionable tips that you can implement today or this week so that you can crush your next PCI Report on Compliance.

And the Report on Compliance next year, and the next, and so on and so on…

1. Begin with the end in mind

In other words, if you don’t know where you’re going how will you know how to get there?

2. Plan the work; work the plan

I was in my master degree program when I first heard this gem. I was learning project management for software development (eons ago) and this made So. Much. Sense.

This tip goes hand in hand with tip #1.

Once you know where you’re going, plan the work.

Then work the plan.

Adjust the plan as needed. 

3. Complete an end to end scope assessment BEFORE you kick off your Report on Compliance

I can’t begin to tell you how much easier your next PCI assessment will be when you have a complete and accurate scope. 

It’s almost mind blowing how much time you’ll save because you won’t be suffering the pains of email hell or chasing things down from the QSA.

In our course, How to Manage Your PCI Scope Without Losing Your Mind, we share our simple 6 step process to continuously manage your scope.

Trust me, you’re going to need this repeatable process for PCI DSS v4.0. 

There’s 11 new requirements that depend on an accurate scope of people, processes, and technologies.

4. Don’t just blindly pick a QSA company. Vet them

Picking the right QSA company matters. Your QSA is an integral part of your ability to successfully navigate the level 5 rapids of a Report on Compliance. 

QSAs who assess with integrity are the best.

5. Consolidate the interviews and observations and SAVE at least 100 hours (or 20k) in wasted, mindless, unnecessary churn

Powerful, right?

Want to save even more? Email support@paymentcardassessments.com and let’s schedule a time to chat!


Discover more from Payment Card Assesments

Subscribe to get the latest posts sent to your email.

10 Essential Tasks To Do BEFORE You Start Your 2023 PCI Report On Compliance

Don’t Start Your 2023 PCI Report on Compliance Without Doing These 10 Essential Tasks FIRST:

The end of the first quarter is quickly approaching. It’s time to get your PCI Compliance house in order.

Because nobody wants to be the next Landry’s and have a $20M fine upheld by federal court.

1. You have a copy of the signed Statement of Work with your QSA

Make sure you have this statement of work at your fingertips throughout your assessment period. This agreement protects you and your QSA for work that is contractually agreed upon.

2. Complete an end-to-end PCI Scope Assessment

The success of your PCI Report on Compliance hinges upon an accurate PCI Scope Assessment.

Your scope assessment includes the who, what, where, when, why, and how of your cardholder data environment and anything or anybody that connects to your cardholder data environment.

Leave a Reply

Discover more from Payment Card Assesments

Subscribe now to keep reading and get access to the full archive.

Continue reading