PCI DSS v3.2 SAQ A-EP, Rev. 1.1 January 2017
© 2006-2017 PCI Security Standards Council, LLC. All Rights Reserved. Page ii
Table of Contents
Document Changes .................................................................................................................. i
Before You Begin .....................................................................................................................iii
PCI DSS Self-Assessment Completion Steps ...................................................................................... iv
Understanding the Self-Assessment Questionnaire ........................................................................... iv
Expected Testing ................................................................................................................................... iv
Completing the Self-Assessment Questionnaire .................................................................................. v
Guidance for Non-Applicability of Certain, Specific Requirements .................................................... v
Legal Exception .................................................................................................................................... v
Section 1: Assessment Information ..................................................................................... 1
Section 2: Self-Assessment Questionnaire A-EP ................................................................ 4
Build and Maintain a Secure Network .................................................................................................... 4
Requirement 1: Install and maintain a firewall configuration to protect data ........................................ 4
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security
parameters .................................................................................................................. 8
Protect Cardholder Data ........................................................................................................................ 12
Requirement 3: Protect stored cardholder data.................................................................................. 12
Requirement 4: Encrypt transmission of cardholder data across open, public networks ................... 13
Maintain a Vulnerability Management Program .................................................................................. 15
Requirement 5: Protect all systems against malware and regularly update anti-virus software or
programs ................................................................................................................... 15
Requirement 6: Develop and maintain secure systems and applications .......................................... 17
Implement Strong Access Control Measures ...................................................................................... 23
Requirement 7: Restrict access to cardholder data by business need to know ................................. 23
Requirement 8: Identify and authenticate access to system components ......................................... 24
Requirement 9: Restrict physical access to cardholder data ............................................................. 29
Regularly Monitor and Test Networks .................................................................................................. 31
Requirement 10: Track and monitor all access to network resources and cardholder data ................ 31
Requirement 11: Regularly test security systems and processes ........................................................ 36
Maintain an Information Security Policy .............................................................................................. 41
Requirement 12: Maintain a policy that addresses information security for all personnel ................... 41
Appendix A: Additional PCI DSS Requirements ........................................................................ 44
Appendix A1: Additional PCI DSS Requirements for Shared Hosting Providers ............................ 44
Appendix A2: Additional PCI DSS Requirements for Entities using SSL/early TLS ....................... 44
Appendix A3: Designated Entities Supplemental Validation (DESV) .............................................. 45
Appendix B: Compensating Controls Worksheet ...................................................................... 46
Appendix C: Explanation of Non-Applicability........................................................................... 47
Section 3: Validation and Attestation Details .....................................................................48