Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 06-29-2007, 05:31 AM
echain echain is offline
Junior Member
 
Join Date: May 2007
Posts: 21
Default Rated audit procedures

Any of you QSA folks out there can tell me where can I get an audit procedure with "high" "medium" "low" risk ratings? On our last (also the first) audit we got from our QSA Auditor the non compliances with these ratings. We're not working with this QSA any longer, and I'd like to get the source of where he got this ratings from.
In a few months we'll have to do another ROC, plus another audit for another subsidiary. For this other one, we've done an internal self assessment. I need to prioritize our ramp up/remediation plans to get ready for these audits. I have no idea where the previous QSA got the ratings for each section of the audit procedure from. I only have the rated gaps, and it's based on the 1.0 version. Any ideas? We haven't selected the new QSA yet .
Reply With Quote
  #2  
Old 06-29-2007, 04:05 PM
lyalc lyalc is online now
Senior Member
 
Join Date: Mar 2007
Posts: 580
Default

To be honest, I suspect any such ratings were probably made up according to your site/environment and hopefully included an assessment of the bang for buck out of fixing various issues/gaps, and ease of implementation/resolution etc.

Lyal
Reply With Quote
  #3  
Old 07-02-2007, 04:54 AM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

For our PCI compliance assessments, we have two "ratings" we issue for findings.
  • Relative Risk
  • Resolution Level of Difficulty

For these two ratings, we use a high, medium and low ranking. We define these rankings as follows.
  • Relative Risk is a subjective evaluation of the severity of the concern and the potential impact on the operations. Items rated as “High” are considered to be of immediate concern and could cause significant operational issues if not addressed in a timely manner. Items rated as “Medium” may also cause operational issues and do not require immediate attention, but should be addressed as soon as possible. Items rated as “Low” could escalate into operational issues, but can be addressed through the normal course of conducting business. It should be noted that relative risk is not indicative of a security risk unless explicitly stated in the detailed finding and recommendation.
  • Resolution Level of Difficulty is a subjective evaluation of the estimated level of difficulty to resolve the concern based on our experience and potential cost. Items rated as “High” are considered to be difficult to resolve and/or will require a significant amount of planning and management involvement/oversight in order to obtain resolution. Items rated as “Medium” are not as difficult to resolve and/or do not require a significant amount of planning, but may be time-consuming to resolve. Items rated as “Low” are items that are not complex and/or require significant amounts of planning and time to resolve.

For our PCI assessments, any issues related to PCI DSS compliance are to be rated with a Relative Risk level of 'High'.

I hope this helps you to understand what your QSA might have been trying to tell you.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #4  
Old 07-04-2007, 02:57 AM
echain echain is offline
Junior Member
 
Join Date: May 2007
Posts: 21
Default

Thanks folks, this helps. We do have an internal rating system.

Cheers
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 04:19 PM.


Copyright (c) The Aegenis Group, Inc.