PCI Assessment
PCI Compliance
PCI Security Standards are developed specifically to protect payment account data throughout the payment lifecycle and enable technology solutions that devalue this data and remove the incentive for criminals to steal it. PCI Compliance ensures that companies accept, process, store or transmit credit card data within a secure environment.
LCM’s PCI Assessment closely examines the scope of credit card usage throughout the organization to determine the correct processes required for and maintaining PCI Compliance. LCM supports our customers by doing a full PCI Assessment or assisting with Self-Assessment Questionnaires.
Get Started on Your PCI Assessment
APPROACH TO PCI ASSESSMENT
LCM’s methodology for the PCI Assessment is based on PCI DSS 3.2. It will compare the current state of how the organization is handling credit card data with the standards set by PCI. The missing controls will not, in every case, need to be implemented, and this will vary depending on budget, resource availability and applicability to a business. A maturity rating will be applied to understand how well the existing controls have been implemented.
LCM recommends that this assessment be completed in six phases:
Review the OSFI Framework
Kick-off Meeting & Data Gathering
Analyze All Gathered Data Information
Prepare Documentation
Draft Review
Final Submission of Deliverables
The following goals are broken down into 12 specific domains and evaluated during LCM’s assessment process.
PCI DSS Goals:
Build and Maintain a Secure Network and Systems
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
PCI ASSESSMENT DELIVERABLES
Four documents will be created as a result of our activities:
Gap Summary: Including executive summary and a list of identified gaps and recommendations.
Cybersecurity Strategy Roadmap: Aligned with the PCI DSS 3.2 Domains.
Roadmap Proposal: A prioritized, project-based approach to remediation, based on the findings from the Gap Summary, that also satisfies budgetary requirements.
Implementation Plan: Mapped to the roadmap, including activities, required resources (people), time estimates to complete, tools/technologies where appropriate, priority, recommended order of implementation.
PCI ASSESSMENT DELIVERY TEAM
Lead Assessor: A seasoned Information Security expert with over 10 years of professional experience in the industry, possessing various certifications and a degree in information security. The assessor has conducted numerous PCI assessments for customers of various sizes across North America.
Virtual CISO: An Information Technology leader with over 20 years of experience in Cyber Security consulting and Managed Security Services, with CISA and CRISC certifications.
Report Writers: Will develop final reports based on the findings of the assessment.