Starting your PCI DSS project
SRM's PCI experts can help you start your PCI compliance project by first assessing and analysing your aims and objectives and then developing a project plan in order to achieve compliance with the Data Security Standard.
The PCI DSS is the benchmark that mitigates security risks and protects payment card data from attack. If you either store, process or transmit payment card data, the PCI DSS is applicable to your organisation. Once you have achieved compliance with the PCI DSS, it must be maintained in order to ensure that sensitive data is kept safe. Being PCI compliant has many benefits:
- Your customers' personal information will be better protected;
- You can promote the fact and enhance the reputation of your organisation because you will be seen to be protecting customer data according to the required standard;
- Your critical business information will be better protected;
- You can demonstrate a higher standard of internal governance.
The roadmap to PCI compliance
is a commonsense approach to data security, so many of its requirements will come as no surprise. However, as the PCI DSS is specific to payment card data (e.g. credit cards and debit cards), there are some unique points that may require some extra effort to achieve. In order to assess the scope of the requirements, it is necessary to understand exactly what systems and processes are likely to be affected within your organisation.

Analysing your business/organisational environment will be crucial in helping you to understand and pinpoint what data you have, how it needs to be secured and what action you'll need to take to comply with the PCI DSS. We can help you with this by:
- Helping you understand the PCI DSS requirements;
- Identifying whether a full assessment by our Qualified Security Assessors is appropriate;
- Defining which SAQ is applicable if a full QSA audit is not required;
- Constructing and auditing an Information Security Policy (ISP);
- Constructing and helping you implement an incident response plan;
- Mapping the flow of your payment card data;
- Analysing your data storage;
- Carrying out risk assessments;
- Identifying your PCI DSS compliance gaps;
- Producing your PCI Remediation Plan.
Contact the PCI Team >