| Control | Status | Evidence / Tool | Notes |
|---|---|---|---|
| Firewall / UTM configured & hardened | |||
| Network segmentation (servers / users / guests) | |||
| Dark web monitoring | |||
| Patch management & automatic updates |
| Policy | Details |
|---|---|
| Password Policy Implemented? | |
| Password Change Frequency | |
| Password Complexity Requirements | |
| MFA Enabled for all users |
| Requirement | Status | Notes |
|---|---|---|
| Firewall Configuration | ||
| Cardholder Data Encryption | ||
| Access Control Policies | ||
| Vulnerability Management | ||
| SOC (Security Operations Center) Monitoring | ||
| Penetration Testing | ||
| User Awareness Training | ||
| Phishing Simulation |
| Requirement | Status | Notes |
|---|---|---|
| BAAs in place for all vendors | ||
| PHI encryption | ||
| Audit controls for PHI | ||
| HIPAA Risk Assessment performed |
| Requirement | Status | Notes |
|---|---|---|
| Secure File Sharing | ||
| Data Retention Policy | ||
| Encryption of Sensitive Financial Data |
| Requirement | Status / Details | Notes |
|---|---|---|
| MDM Platform | ||
| Device Coverage | ||
| Automated Enrollment | ||
| OS Version Compliance | ||
| Passcode / Screen Lock Policy | ||
| Device Encryption | ||
| Jailbreak / Root Detection | ||
| Compliance Reporting | ||
| App Allow/Block Lists | ||
| Remote Wipe / Lost Mode | ||
| Containerization / BYOD |
Place these files in the same folder as this HTML to enable preview & download:
PCI_DSS_4.0_SAQ_Comparison_Clean.pdfPCI-DSS-v4_0_1-SAQ-A.pdfPCI-DSS-v4-0-1-SAQ-B.pdfPCI-DSS-v4-0-1-SAQ-C.pdfPCI-DSS-v4-0-1-SAQ-D.pdf