February 15, 2010

Case Studies of Using GAIT-R to Scope PCI DSS Compliance

The Institute of Internal Auditors

The PCI DSS (Payment Card Industry Data Security Standard) is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data. Using GAIT-R to scope PCI DSS compliance adds value, provides efficiency and effectiveness for use of resources for management, security, and audit. The article provides a working methodology to identify the appropriate combination of key controls to include in the scope of a PCI DSS compliance audit.