Loading Vaultize
Skip to main content

Compliance/Security frameworks/PCI DSS v4.0.1

Twelve requirements: eleven controls leave evidence in the file.

PCI DSS protects account data wherever it is stored, processed or sent. When it sits in a document, Vaultize adds records that stay with the data.

G1G2G3G4G5G6
G1Secure network0 outcomes
Read againstPCI DSS v4.0.1, Requirements and Testing ProceduresPCI DSS v4.0.1 · June 2024
  • Contractual standard, not law
  • Capability mapping, not validation
  • PCI DSS v4.0.1 · June 2024
11sub-requirements across 5 of 12

The answer in 30 seconds

Vaultize adds file-level records to 11 sub-requirements under Requirements 3, 4, 7, 8 and 10. Network, configuration, malware, software, physical, testing and policy requirements belong to other control owners.

The standard in one view

Six goals. Twelve requirements. Where file evidence lands.

PCI DSS groups its twelve requirements under six goals. Select a goal to see which of its requirements a governed file can evidence.

G1SECURENETWORKG2ACCOUNT DATAG3VULNERABILITYPROGRAMG4ACCESSCONTROLG5MONITOR ANDTESTG6SECURITYPOLICY

G1

Secure network

Goal: Build and Maintain a Secure Network and Systems. Requirements 1 and 2.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Network security controls and secure configurations belong to the network and platform owners. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Requirement by requirement

    What each requirement asks. What the file can answer.

    Requirement numbers are from PCI DSS v4.0.1. Each description is a one-line paraphrase; read the requirement, its testing procedures and applicability notes in the standard. Each row is a capability mapping for account data held in documents, not a validation.

    Using this page

    Where these rows fit in a PCI DSS assessment.

    PCI DSS compliance is validated by an assessor or through a self-assessment questionnaire. This page is evidence for the requirements that touch documents.

    1. 1

      Scope the environment

      Identify where account data is stored, processed and sent, including documents.

    2. 2

      Choose the validation route

      Report on Compliance with a Qualified Security Assessor, or a Self-Assessment Questionnaire.

    3. 3

      Gather the evidence

      Collect records for each requirement in scope. These rows belong here.

      Bring the eleven rows above as evidence for the requirements that cover account data in documents.

    4. 4

      Assess

      The assessor tests each requirement against its testing procedures.

    5. 5

      Attest

      Complete the Attestation of Compliance for the acquirer or payment brand.

    Responsibility boundary

    Controls support validation. A product does not confer it.

    Vaultize contributes technical controls and evidence for account data held in documents. It is not a payment system and is not a PCI-validated product. It does not define scope, perform the assessment, or attest to compliance. Validation is performed by a Qualified Security Assessor or through the applicable Self-Assessment Questionnaire. Read the standard and obtain qualified advice before relying on this page.

    A practical next step

    Bring one document that carries account data.

    We will show which requirements the governed document can evidence today. We will name the control owner responsible for the rest.

    Request a compliance mapping session