PCI Management Use Case Design
The Archer PCI Management guides you through identifying and defining cardholder data flows and environments, engaging proper stakeholders, completing self-assessment questionnaires (SAQs), testing and gathering evidence for all required controls, and managing the gap remediation process.
On this page
Architecture Diagram
The following diagram shows the relationships between the applications in the PCI Management use case.
Applications and Questionnaires
Application/ |
Description |
---|---|
Control Scoping Unit |
The Control Scoping unit application stores a copy of the ROC controls and Custom Control for each project. A set of data feeds link the ROC controls from this application to a Compliance Project record. Each ROC Control record allows for the documentation of in-place requirements commentary and the reporting methodology for each testing procedure. Each Custom Control requires the assessed entity to provide additional supporting documentation and evidences for assessment. Control Scoping Unit is a standard application which other use cases '' use to maintain historical control versioning. Control Scoping Unit has replaced the PCI Controls application from version 6.11 and later. |
Compliance Project |
The Compliance Project application functions as the hub of the PCI Management use case. It allows you to link the cardholder data environments you want to include for the Self-Assessment Questionnaire and the ROC. You can also identify and record stakeholders, personnel interviewed, and the Qualified Security Assessor. Additionally, this application allows you to define the validation type for your SAQ questionnaire, and includes a mail merge template to create the standard PCI Report On Compliance. You can use this application to conduct assessments for PCI DSS Version 3.2.1 and Version 4.0. |
PCI 3.2.1 Self-Assessment (SAQ) |
The Self-Assessment questionnaire displays questions based on the SAQ type selected in the associated project. This questionnaire determines an organization's overall compliance with the standard PCI requirements 3.2.1. |
PCI 4.0 Self-Assessment (SAQ) |
The Self-Assessment questionnaire displays questions based on the SAQ type selected in the associated project. This questionnaire determines an organization's overall compliance with the standard PCI requirements 4.0. |
Control Matrix Template |
This questionnaire displays within Control Scoping Unit for Custom Controls. The Entity being assessed should provide the control implementation details in the template. |
Risk Analysis Template |
This questionnaire displays within the Control Scoping Unit for Custom Controls. The Entity being assessed should perform a targeted risk analysis in the template. |
Primary Controls |
The Primary Controls application serves as a central repository for procedures, baselines, and activities that are mapped to corporate control standards, establishing the foundation for enterprise-wide risk monitoring and compliance measurement. Primary Controls are categorized into two types: Technical and Process. Based on the selected type, different pieces of information are captured and different testing options are made available. Note: The Primary Controls application is included in the Enterprise Catalog package. |
Question Library |
The Question Library application stores assessment questions that you can reference and copy into a questionnaire. Each question is stored as an individual record, and each record contains information including the question and answer text as well as information necessary to display and score the question. Depending on the solution that you have licensed, the Question Library contains a large set of pre-built questions by default. In addition, you can add new questions and store them in the Question Library. |
Applications |
The Applications application enables organizations to store details related to their business operations, such as payment intake or customer account information. The Applications application stores all software applications used by the organization to perform business operations. You can view how an application is used, the people that use it, and the devices on which the application is installed. You can also track the business impact, customer impact, and licensing details, and associate it with other aspects of the enterprise infrastructure. Note: The Applications application is included in the Enterprise Catalog package. |
Cardholder Data Environment |
The PCI Cardholder Data application enables organizations to document data flows, database and files stores, applications, devices, facilities and service providers that make up the cardholder data environment. This application also captures the executive summary of the Report On Compliance (ROC) and allows you to attach a network diagram and payment card business overview. |
Devices |
The Devices application serves as a central repository for knowledge, such as criticality, about IT devices and which applications they support. You can manage devices to ensure that they are protected according to management expectations. The application is also associated with other aspects of the enterprise infrastructure. Note: The Devices application is included in the Enterprise Catalog package. |
Facilities |
The Facilities application maintains a listing of all organizational facilities, such as data centers and branches. You can document and review all information associated with a specific facility, such as contact personnel, location information, and technologies associated with the location. Note: The Facilities application is included in the Enterprise Catalog package. |
Information Assets |
The Information Assets application allows you to manage a repository of information assets, such as credit card data, financial forecasts, employee Social Security numbers, and trademarks. Use this application to perform online assessments to determine information classification ratings and required retention periods. Link information assets to the business processes they support, the applications where they are managed, and the facilities where they are housed. Note: The Information Assets application is included in the Enterprise Catalog package. |
Control Procedures |
The Control Procedures application serves as a central repository for instances of control procedures, baselines and activities that are mapped to corporate Primary Controls, establishing the foundation for enterprise-wide risk monitoring and compliance measurement. Control Procedures are categorized into two types: Technical and Process. Based on the selected type, different pieces of information are captured and different testing options are made available. Note: The Control Procedures application is included in the Enterprise Catalog package. |
Evidence Repository |
Links the Evidence Repository application to the Primary Controls and Control Procedures applications, to enable you to track evidence collection for controls you want to continuously monitor. |
Access roles
Access Role |
Description |
---|---|
PCI Executive Sponsorship |
This role gives executive-level management read-only rights to the PCI Management use case; create, read, and update rights to use case reports, Findings, and Exceptions; and read-only rights to the SAQ. |
PCI Internal Stakeholders |
This role gives internal stakeholders read-only rights to the PCI Management use case; read and update rights to the SAQ and Findings; create, read, update, and delete rights to the PCI Management use case reports other than the Findings reports; and create, read, and update rights to Exceptions. |
PCI Project Team |
This role gives the project team rights to create a Compliance Project and its SAQ. The role has create, read, update, and delete rights to the PCI Management use case and its reports. |
PCI Admin |
This role gives the admin the right to create, read, update, and delete rights for all applications within PCI Management use case. This role is designated for PCI applications as a default configuration administrator. |
Note: For detailed, page-level access rights, see the Data Dictionary.
Dashboards
Dashboard |
Description |
---|---|
PCI Executive Dashboard |
The PCI Executive Dashboard is intended for the PCI Executive Sponsorship role. |
PCI Project Team Member Dashboard |
This dashboard is for use to track control assessment activities, display distribution of work across the entire PCI team, and provides an overview of the entire compliance project. This is for use by the PCI Project Team Member role. |
PCI Internal Stakeholder Dashboard |
This dashboard is for use by an internal compliance stakeholder to complete tasks such as reviewing control ownership, completing self-assessment questionnaires, and resolving open issues. |
Data Feeds
PCI Data Feed | Description |
---|---|
Autoscope_Card_Data_Environment_From Business_Processes_PATH_1.dfx5 Autoscope_Card_Data_Environment_From Business_Processes_PATH_2.dfx5 Autoscope_Card_Data_Environment_From Business_Processes_PATH_3.dfx5 Autoscope_Card_Data_Environment_From Business_Processes_PATH_4.dfx5 |
These data feeds scope the first, second, third, and fourth path of assets into the Cardholder Data Environment (CDE) based on the selected business process. |
Generate PCI Control Scoping Unit v6.11.dfx5 |
This data feed generates PCI Controls that are specific to a Compliance Project. |
Auto-Link PCI SAQ Findings To PCI Control Scoping Unit.dfx5 |
This data feed links generated findings from the Self-Assessment Questionnaire (SAQ) to their corresponding control scoping records . |
Auto-Generate Findings For Control Scoping Unit v6.11.dfx5 |
This data feed creates a finding for any Control Scoping Unit record that is assessed as Not in Place, In Place with Remediation, or In Place with CCW. |
Data Dictionary
The PCI Management Data Dictionary contains configuration information for the use case.
You can obtain the Data Dictionary for the solution by contacting your Archer Technologies Account Representative.