Compliance/Security frameworks/PCI DSS v4.0.1
Twelve requirements: eleven controls leave evidence in the file.
PCI DSS protects account data wherever it is stored, processed or sent. When it sits in a document, Vaultize adds records that stay with the data.
- Contractual standard, not law
- Capability mapping, not validation
- PCI DSS v4.0.1 · June 2024
The answer in 30 seconds
Vaultize adds file-level records to 11 sub-requirements under Requirements 3, 4, 7, 8 and 10. Network, configuration, malware, software, physical, testing and policy requirements belong to other control owners.
The standard in one view
Six goals. Twelve requirements. Where file evidence lands.
PCI DSS groups its twelve requirements under six goals. Select a goal to see which of its requirements a governed file can evidence.
G1
Secure network
Goal: Build and Maintain a Secure Network and Systems. Requirements 1 and 2.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Network security controls and secure configurations belong to the network and platform owners. A governed file adds no evidence here.
- Evidence to retain
- None from Vaultize.
Requirement by requirement
What each requirement asks. What the file can answer.
Requirement numbers are from PCI DSS v4.0.1. Each description is a one-line paraphrase; read the requirement, its testing procedures and applicability notes in the standard. Each row is a capability mapping for account data held in documents, not a validation.
Using this page
Where these rows fit in a PCI DSS assessment.
PCI DSS compliance is validated by an assessor or through a self-assessment questionnaire. This page is evidence for the requirements that touch documents.
- 1
Scope the environment
Identify where account data is stored, processed and sent, including documents.
- 2
Choose the validation route
Report on Compliance with a Qualified Security Assessor, or a Self-Assessment Questionnaire.
- 3
Gather the evidence
Collect records for each requirement in scope. These rows belong here.
Bring the eleven rows above as evidence for the requirements that cover account data in documents.
- 4
Assess
The assessor tests each requirement against its testing procedures.
- 5
Attest
Complete the Attestation of Compliance for the acquirer or payment brand.
Responsibility boundary
Controls support validation. A product does not confer it.
Vaultize contributes technical controls and evidence for account data held in documents. It is not a payment system and is not a PCI-validated product. It does not define scope, perform the assessment, or attest to compliance. Validation is performed by a Qualified Security Assessor or through the applicable Self-Assessment Questionnaire. Read the standard and obtain qualified advice before relying on this page.
Official references
Read the source before relying on the mapping.
Goals, requirement titles and numbers come from the first item. The others are the Council’s own material.
A practical next step
Bring one document that carries account data.
We will show which requirements the governed document can evidence today. We will name the control owner responsible for the rest.
