PCI DSS preparation

Reduce and control the cardholder-data scope before piling up controls.

IKNSA maps the payment flows, responsibilities and dependencies to qualify the scope, the gaps and the appropriate validation mode.

Evidence chainObserve · qualify · prioritise
  1. Scope
  2. Findings
  3. Risks
  4. Trajectory

The decision point

The first measure of control is knowing where card data passes, rests or can be influenced.

The audit follows the payment journeys, the pages, terminals, applications, networks, providers and administrative access. It identifies scope-reduction opportunities, verifies segmentation and organises the evidence according to the role and the validation mode.

TriggerA new payment journey, an acquirer requirement or an uncertain scope
ScopeFlows, components, providers, networks and access
Expected outputA qualified scope and a preparation plan

Working scope

The dimensions examined together.

The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.

  1. Card data flows and storage
  2. Payment pages, scripts and terminals
  3. Network segmentation and connected components
  4. Identities, access and logging
  5. Providers, responsibilities and attestations
  6. Tests, scans, evidence and validation mode

A usable result

A defensible scope and organised evidence.

The read-out distinguishes the controls that apply directly, the dependencies on providers and the architecture decisions capable of durably reducing the scope and the validation effort.

  1. 01Flow map and proposed scope
  2. 02Responsibility and provider matrix
  3. 03Technical, organisational and documentary gaps
  4. 04Preparation plan, tests and evidence

Method

An engagement that stays readable from scope to decision.

01

Scope

Fix the entities, services, assets, periods and frameworks actually examined.

02

Observe

Cross-check interviews, documents, configurations and operational results without relying on declarations alone.

03

Prioritise

Connect each finding to its business impact, its likelihood and the controls already in place.

04

Decide

Produce a costed trajectory with owners, deadlines, dependencies and expected evidence.

Point of vigilance

What the engagement must make explicit.

The final qualification and the validation mode depend on the contractual context, the volume, the journeys and the authorised actors. The preparation engagement must not be confused with an attestation issued outside its mandate.

The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.

Frame this engagement See Audit & compliance Start with a guided assessment

First conversation

Let’s discuss the next point of control for your information system.

A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.