that are not required to undergo an annual audit with a QSA, Internet Security Auditors provides a support service for the preparation of the self-assessment questionnaire, previously carrying out a review of the current state of compliance with the requirements established by PCI DSS.
This questionnaire applies to all organizations (merchants or service providers) that must validate their compliance with PCI DSS, but are not required to undergo an annual audit with a QSA.
The project is structured in the following phases:
This phase aims to analyze the payment card data flows handled by the organization, determine the type of SAQ questionnaire that must be completed to validate PCI DSS compliance, and understand the level of compliance with the standard.
Based on the non-compliances identified by the PCI QSA consulting team, an action plan document will be drafted defining recommendations on how to resolve these non-conformities and achieve full compliance with the PCI DSS standard.
This phase involves completing the SAQ questionnaire using the information obtained in the previous phases.