InteliPath will perform a gap analysis and perform the required testing to be able to inform the client of the controls that need remediation to achieve PCI compliance. The assessment will include a review of the cardholder production network (including vulnerability and penetration testing) and supporting technical documentation. The assessment process may include interviews with company personnel to determine what PCI requirements are in place and where remediation is required.
The first phase of the project will involve reviewing and validating the current cardholder network environment, policies and procedures against the PCI Data Security Standard (DSS). The methodology for validation will include:
- Review of current cardholder environment technology and security features
- Mapping touch points to the corporate network
- Examining access points and network components for security shortcomings from a PCI perspective
- Verification that current documented controls meet the specific PCI DSS requirements
- Scans and penetration tests to validate that the client has attained an appropriate level of security