PCI DSS v3.2 SAQ C, Rev. 1.1 January 2017
© 2006-2017 PCI Security Standards Council, LLC. All Rights Reserved. Page ii
Table of Contents
Document Changes .................................................................................................................. i
Before You Begin .....................................................................................................................iii
PCI DSS Self-Assessment Completion Steps ...................................................................................... iii
Understanding the Self-Assessment Questionnaire ........................................................................... iv
Expected Testing ................................................................................................................................... iv
Completing the Self-Assessment Questionnaire .................................................................................. v
Guidance for Non-Applicability of Certain, Specific Requirements .................................................... v
Legal Exception .................................................................................................................................... v
Section 1: Assessment Information ..................................................................................... 1
Section 2: Self-Assessment Questionnaire C ...................................................................... 4
Build and Maintain a Secure Network and Systems ............................................................................. 4
Requirement 1: Install and maintain a firewall configuration to protect data ........................................ 4
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security
parameters .................................................................................................................. 6
Protect Cardholder Data ........................................................................................................................ 12
Requirement 3: Protect stored cardholder data.................................................................................. 12
Requirement 4: Encrypt transmission of cardholder data across open, public networks ................... 14
Maintain a Vulnerability Management Program .................................................................................. 16
Requirement 5: Protect all systems against malware and regularly update anti-virus software or
programs ................................................................................................................... 16
Requirement 6: Develop and maintain secure systems and applications .......................................... 18
Implement Strong Access Control Measures ...................................................................................... 20
Requirement 7: Restrict access to cardholder data by business need to know ................................. 20
Requirement 8: Identify and authenticate access to system components ........................................ 21
Requirement 9: Restrict physical access to cardholder data ............................................................. 25
Regularly Monitor and Test Networks .................................................................................................. 30
Requirement 10: Track and monitor all access to network resources and cardholder data ................ 30
Requirement 11: Regularly test security systems and processes ........................................................ 33
Maintain an Information Security Policy .............................................................................................. 39
Requirement 12: Maintain a policy that addresses information security for all personnel ................... 39
Appendix A: Additional PCI DSS Requirements ........................................................................ 43
Appendix A1: Additional PCI DSS Requirements for Shared Hosting Providers ............................ 43
Appendix A2: Additional PCI DSS Requirements for Entities using SSL/early TLS ...................... 43
Appendix A3: Designated Entities Supplemental Validation (DESV) .............................................. 44
Appendix B: Compensating Controls Worksheet ...................................................................... 45
Appendix C: Explanation of Non-Applicability........................................................................... 46
Section 3: Validation and Attestation Details .....................................................................47