pci risk assessment

8
Risk Assessment for PCI Compliance [Mandatory as per Requirement 12.1.2] Sign up for FREE www.smart-ra.com

Upload: smart-assessment

Post on 10-Jun-2015

1.141 views

Category:

Technology


0 download

DESCRIPTION

Meet the Risk Assessment Requirement 12.1.2 of PCI 2.0 with SMART Risk Assessment. www.smart-ra.com

TRANSCRIPT

Page 1: PCI Risk Assessment

Risk Assessment for PCI Compliance [Mandatory as per Requirement 12.1.2]

Sign up for FREE www.smart-ra.com

Page 2: PCI Risk Assessment

• PCI 2.0 requires a formal and structured risk assessment methodology.

• Meet the requirement with SMART

Sign up for FREE www.smart-ra.com

Page 3: PCI Risk Assessment

Requirement 12.1.2 emphasizes the need for a structured and formal risk assessment methodology.

• “Requirement 12.1 Establish, publish, maintain, and disseminate a security policy that accomplishes the following:

• Requirement 12.1.2 Includes an annual process that identifies threats, and vulnerabilities, and results in a formal risk assessment.(Examples of risk assessment methodologies include but are not limited to OCTAVE, ISO 27005 and NIST SP 800-30.)”

Sign up for FREE www.smart-ra.com

Page 4: PCI Risk Assessment

Scope Establishment Identify Assets Identify Threats

Profiling: Add Controls Identify Vulnerabilities

Sign up for FREE www.smart-ra.com

Page 5: PCI Risk Assessment

•Search Assets•Bulk Upload of Assets•Use predefined Standard Assets•Enter CIA values of Assets to generate Asset Value

•Simple view ofAsset and Threat Mapping•Search and Find Threats

•Search Vulnerabilities•Prioritize with Level of Vulnerability

•Do Profiling by Location•Vulnerabilities are also considered in defining Controls•Integrate Action Management Module to implement Controls

www.smart-ra.com

Page 6: PCI Risk Assessment

•Monitor your Organizational Risk Health•Measure Effectiveness of Controls

•Assign Actions to Implement Controls or Manage Incidents

•Create and Manage Policy and Procedure documents.•Manage Document Review

•Create Surveys to identify organizational vulnerabilities•Represent findings with Survey Reports

•Manage Incidents by applying relevant Controls

www.smart-ra.com

•Risk AssessmentReport•Asset Report•Threat Report•BLSS Report, etc

Page 7: PCI Risk Assessment

• Meet RA requirements of PCI 2.0.

• Use RA for preparation of PCI Compliance.

• Reduce risks in your organization and improve security.

• Also help in meeting ISO 27001 and other Risk Management Standards in one go…

• Save 80% of your time and cost on risk assessment.

Sign up for FREE www.smart-ra.com