1. Gap Assessment Scope & Methodology
Define the boundaries and execution tactics of the internal review.
- Assessment Framework: Explicit alignment with the current PCI DSS v4.0 testing tracks.
- Discovery Methods: Combination of technical configuration reviews, personnel interviews, and physical facility walk-throughs.
- Systems Evaluated: Total count of network segments, servers, firewalls, locations, and payment terminals scanned during the gap analysis.
2. Requirement-by-Requirement Deficiency Summary
A diagnostic breakdown mapping missing controls directly to the 12 PCI requirements.
- Goal-Level Status: High-level pass/fail summary of the 6 core PCI security goals.
- Identified Vulnerabilities: Specific listing of missing technical or administrative controls (e.g., “Requirement 8.4.2: Lack of Multi-Factor Authentication on internal administrative accounts”).
- Process Gaps: Identification of outdated documentation, unperformed logs, or missing annual staff training certifications.
3. Technical Vulnerability Scan & Pentest Baseline
The baseline performance data collected from early internal and external testing.
- Internal Scan Findings: Results from preliminary vulnerability scans targeting the Cardholder Data Environment (CDE).
- ASV Scan Status: Progress update on external network scans managed via an Approved Scanning Vendor.
- Penetration Test Gaps: Early weaknesses identified in network segment isolation or web application boundaries.
4. Risk Prioritization & Impact Matrix
A logical categorization ranking which discovered flaws pose the highest security or audit risk.
- Critical-Risk Gaps: Immediate failure items that actively expose raw cardholder data (e.g., unencrypted stored data or open default passwords).
- Major-Risk Gaps: Non-compliant configurations that compromise system integrity (e.g., missing network security control logs).
- Administrative Gaps: Documentation errors or unformalized policies that do not risk data breach but fail compliance checks.
5. Remediation Roadmap & Action Plan
The step-by-step blueprint detailing how the business could fix each deficiency before the final QSA audit.
- Corrective Actions: Specific technical or operational fixes assigned to each identified gap.
- Resource Allocation: Assignment of clear internal ownership (e.g., IT Operations, Security Team, DevOps) to each task.
- Target Milestones: Strict timeline schedules detailing completion dates for patching, re-testing, and final sign-off