Itci Itacl Pci 0321 Lb

Auditor's Checklist: PCI Audit Compliance
Practical guidance on how to prepare for successful audits 
Payment CardIndustry (PCI)
Research Sponsor
Table of Contents
Executive Overview
Introduction to PCI4 What Are the Benefits of PCI Compliance?
The Auditor’s Perspective on PCI5 Why Audit?6 Who Is Responsible for PCI?9 Management’s Role in the Audit Process10 What Auditors Want To See11 Auditors Like…11 Auditors Don’t Like…
11 How Companies (Inadvertently orIntentionally) Help or Hinder Auditors
Who Should Talk to the Auditors?
PCI Audit Checklist14 Theme 1: Building and Maintaininga Secure Network Audit Testing15 Theme 2: Protecting Cardholder Data19 Theme 3: Maintaining a VulnerabilityManagement Program20 Theme 4: Implementing Strong AccessControl Measures21 Theme 5: Regularly Monitoring andTesting Networks22 Theme 6: Maintaining an InformationSecurity Policy23 Audit Reporting
Preparing for an Audit
Communicating with Auditors
AppendicesAppendix A: Glossary of Terminologyand AbbreviationsAppendix B: PCI Data Security StandardAppendix C: PCI Security Audit ProceduresAppendix D: PCI Self-Assessment Questionnaire
 About the IT Compliance Institute
The IT Compliance Institute (ITCi) strives to be aglobal authority on the role of technology in businessgovernance and regulatory compliance. Throughcomprehensive education, research, and analysisrelated to emerging government statutes and affectedbusiness and technology practices, we help organizationsovercome the challenges posed by today’s regulatory environment and find new ways to turn complianceefforts into capital opportunities.ITCi’s primary goal is to be a useful and trusted resourcefor IT professionals seeking to help businesses meet privacy, security, financial accountability, and otherregulatory requirements. Targeted at CIOs, CTOs,compliance managers, and information technology professionals, ITCi focuses on regional- and vertical-specific information that promotes awareness andpropagates best practices within the IT community.
For more information, please visit: www.itcinstitute.com
Comments and suggestions to improve the IT Audit Checklists are always encouraged. Please send yourrecommendations toeditor@itcinstitute.com.

