Reviews must be carried out at least every three months, by PCI DSS compliance program personnel identified under A3.1.3, to verify BAU activities are followed. They must include: confirmation that all BAU activities, including those required by A3.3.1, A3.2.2 and A3.2.6, are happening; confirmation that staff follow security policies and operating procedures (for example reviewing logs each day, reviewing NSC rulesets, and applying configuration standards to newly built systems); documentation of how the reviews were done, including how each BAU activity was verified; collection of documented evidence needed for the annual assessment; review and sign-off of the results by compliance program personnel per A3.1.3; and retention of records and documentation covering all BAU activities for at least 12 months. Related PCI DSS requirements: all twelve. Guidance: the aim is to confirm activities occur, not to redo them. Applies only to designated entities. Objective under the customized approach: not eligible for the customized approach; only the defined approach can be used.
PCI DSS 4.0 A3.3.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.