Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants
Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants

PCI Compliance Services


Sunera is a PCI Qualified Security Assessor (QSA) and an Approved Scanning Vendor (ASV), and provides a variety of services including on-site PCI data security audits, remediation assistance, security scans, secure code audits and compliance reporting to payment card industry members, merchants, and service providers that are required to achieve and maintain PCI compliance. The Payment Card Industry Security Standards Council (PCI SSC) requires the use of PCI Qualified Security Assessors to perform PCI on-site security audits using the PCI Security Audit Procedures to assess compliance with the PCI Data Security Standard.




PCI Services: Audit, Scanning, Compliance, Testing, Remediation Assistance, Advisory & Consulting

To learn more about Sunera's PCI Compliance Services, please complete the following brief e-mail form and one of Sunera's Directors will contact you.






Or follow one of the links below and request a price quote for our service offerings.


Price Quote

     Request a price quote for:

Merchants
Service Providers


Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants

Payment Card Industry (PCI) Compliance


As a Merchant or Service Provider, you are responsible for ensuring that you achieve and maintain compliance with the Payment Card Industry (PCI) Data Security Standard (DSS). The DSS defines requirements for the protection of consumers' payment card information while stored, in transit or during processing. Organizations that fail to comply with the PCI DSS potentially face significant fines, loss of customer goodwill, and may lose the ability to accept credit cards for payment.


PCI Service Offerings


  • PCI Approved Scanning Vendor, PCI ASV, PCI Qualified Security Assessor, PCI QSA

Each payment card brand assigns merchants and service providers with a 'level', based on the organization's annual volume of payment card transactions. While every merchant and service provider must comply with all applicable requirements in the DSS, reporting requirements differ by 'level'. Organizations of all levels are required to have quarterly external network scans performed by an Approved Scanning Vendor (ASV). Additional reporting requirements include either the completion of a Self-Assessment Questionnaire or an onsite audit performed by a Qualified Security Assessor (QSA). Sunera is a PCI Qualified Security Assessor (QSA) and an Approved Scanning Vendor (ASV).

We assist clients in meeting and maintaining their PCI compliance requirements by providing sustainable solutions that may be integrated with other compliance requirements to reduce the overall cost of compliance. All of Sunera's PCI services are located in the following table.


Sunera PCI Services
Annual Onsite Audit
ASV & Internal Network Scans
Automated Network and System Data Searches
Continued Compliance Programs
Gap Analysis/Compliance Roadmap
Penetration Testing
Remediation Assistance
Secure Network and Systems Architecture
Scoping Assistance
Self Assessment Questionnaire Assistance
Web and Application Code Reviews
Wireless Analysis

Resources


All of Sunera's PCI professionals currently hold the Qualified Security Assessor (QSA) designation as required by PCI SSC. In addition, our security professionals also maintain one or more of the following certifications: Certified Information Systems Security Professional (CISSP); Certified Information Systems Auditor (CISA); Certified Information Security Manager (CISM); and Certified Information Privacy Professional (CIPP). Our Professionals have delivered multiple engagements to all levels of merchants and service providers across a broad spectrum of industries in the public, private, government and not-for-profit sectors.


Sample PCI Assessment Process Overview


The Sunera assessment process minimizes the impact on business operations by providing a logical, structured approach that emphasizes productivity and maximizes return on investment. A brief example of how Sunera conducts assessments follows:


  • Define the scope of work to be performed during the assessment.
  • Conduct a pre-assessment meeting to establish expectations, identify the key players in the assessment process, and to provide guidance to the client.
  • Receive and review off-site all relevant policies, procedures, and technical documentation.
  • Arrive on-site and perform the data security assessment process as detailed in the initial scope of work.
  • Provide an initial statement of findings which identifies deficiencies and provides recommendations so that remediation efforts may begin as promptly as possible.
  • Generate a Report on Compliance.
  • Conduct quarterly and/or on-demand network scans to fulfill ongoing PCI compliance requirements.
Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants

Price Quote

Request a price quote for Sunera's PCI Services:

Merchants
Service Providers



PCI Requirements

Download a copy of the PCI requirements for Merchants or Service Providers here:

Merchants
Service Providers

 


PCI Reference Guide

PCI requirements are implemented by the PCI Security Standards Council (SSC); however each payment card brand has its own individual data security program requirements that must be met. Links to the PCI SSC and each brand’s individual compliance program are included below.


Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants
Sunera:Home     Services     Industries     About     News & Events     Contact Us     Careers
Services:Internal Audit     IT Audit     Sarbanes-Oxley     Information Security     PCI Compliance     Data Privacy     IFRS Conversion     ACL Consulting & Training
  Forensic & Fraud Auditing     Model Audit Rule     Business Advisory     IT Advisory     SAP Services     ERP Controls     Approva Integration     Project Risk
Contact Us:Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants  info@sunera.com     Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants  (888) SUNERA1     Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants  Office Locations

Sunera Privacy Policy
Sunera Sarbanes-Oxley (SOX) & Internal Audit Consultants