Global (PCI Security Standards Council; payment software vendors seeking validation and listing)

PCI SSF

156 controls. 198 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

156 controls 198 frameworks share controls with it Global (PCI Security Standards Council; payment software vendors seeking validation and listing) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
PCI-SSF-01Information security program management0
PCI-SSF-02Board and management oversight0
PCI-SSF-03Risk appetite and tolerance for IT risk55
PCI-SSF-04Security policy framework0
PCI-SSF-05Roles and responsibilities definition110
PCI-SSF-06Network security and segmentation31
PCI-SSF-07Endpoint protection and detection10
PCI-SSF-08Application security controls26
PCI-SSF-09Encryption and key management62
PCI-SSF-10Secure configuration standards32
PCI-SSF-11Business continuity planning and testing21
PCI-SSF-12Disaster recovery procedures66
PCI-SSF-13Third-party dependency management0
PCI-SSF-14Critical service identification32
PCI-SSF-15Communication and escalation procedures45
PCI-SSF-16Due diligence and onboarding56
PCI-SSF-17Contractual security requirements55
PCI-SSF-18Ongoing monitoring and assessment0
PCI-SSF-19Concentration risk management0
PCI-SSF-20Exit strategy and transition planning0
PCI-SSF-21Incident detection and classification72
PCI-SSF-22Incident response and containment0
PCI-SSF-23Regulatory reporting requirements0
PCI-SSF-24Customer notification procedures72
PCI-SSF-25Post-incident review and improvement72
SSLC-1.1Security Responsibility and Resources0
SSLC-10.1Software Integrity0
SSLC-11.1Stakeholder Communication0
SSLC-12.1Software Update Integrity and Verification0
SSLC-2.1Software Security Policy0
SSLC-3.1Software Security Personnel Skills0
SSLC-4.1Threat Identification and Risk Mitigation0
SSLC-5.1Software Design Security0
SSLC-6.1Secure Coding Practices1
SSLC-7.1Security Testing1
SSLC-8.1Vulnerability Disclosure and Response0
SSLC-9.1Change Management4
SSS-1.1Critical Asset Identification0
SSS-1.2Critical Asset Protection0
SSS-10.1Sensitive Authentication Data (Module A)0
SSS-11.1Terminal Software Module Requirements (Module B)0
SSS-2.1Sensitive Data Inventory and Protection0
SSS-3.1Critical Asset Cryptographic Protection0
SSS-4.1Authentication and Access Control0
SSS-5.1Attack Detection0
SSS-6.1Threat and Vulnerability Management0
SSS-7.1Secure Software Updates0
SSS-8.1Vendor Security Guidance0
SSS-9.1Account-Data Protection (Module A)0
1.1Secure Software Standard 1.1 (Critical Asset Identification)0
1.2Secure Software Standard 1.2 (Critical Asset Identification)0
1.3Secure Software Standard 1.3 (Critical Asset Identification)0
10.1Secure Software Standard 10.1 (Threat and Vulnerability Management)0
10.2Secure Software Standard 10.2 (Threat and Vulnerability Management)0
11.1Secure Software Standard 11.1 (Secure Software Updates)0
11.2Secure Software Standard 11.2 (Secure Software Updates)0
12.1Secure Software Standard 12.1 (Software Vendor Implementation Guidance)0
2.1Secure Software Standard 2.1 (Secure Defaults)0
2.2Secure Software Standard 2.2 (Secure Defaults)0
2.3Secure Software Standard 2.3 (Secure Defaults)0
2.4Secure Software Standard 2.4 (Secure Defaults)0
2.5Secure Software Standard 2.5 (Secure Defaults)0
3.1Secure Software Standard 3.1 (Sensitive Data Retention)0
3.2Secure Software Standard 3.2 (Sensitive Data Retention)0
3.3Secure Software Standard 3.3 (Sensitive Data Retention)0
3.4Secure Software Standard 3.4 (Sensitive Data Retention)0
3.5Secure Software Standard 3.5 (Sensitive Data Retention)0
3.6Secure Software Standard 3.6 (Sensitive Data Retention)0
4.1Secure Software Standard 4.1 (Critical Asset Protection)0
4.2Secure Software Standard 4.2 (Critical Asset Protection)0
5.1Secure Software Standard 5.1 (Authentication and Access Control)0
5.2Secure Software Standard 5.2 (Authentication and Access Control)0
5.3Secure Software Standard 5.3 (Authentication and Access Control)0
5.4Secure Software Standard 5.4 (Authentication and Access Control)0
6.1Secure Software Standard 6.1 (Sensitive Data Protection)0
6.2Secure Software Standard 6.2 (Sensitive Data Protection)0
6.3Secure Software Standard 6.3 (Sensitive Data Protection)0
7.1Secure Software Standard 7.1 (Use of Cryptography)0
7.2Secure Software Standard 7.2 (Use of Cryptography)0
7.3Secure Software Standard 7.3 (Use of Cryptography)0
7.4Secure Software Standard 7.4 (Use of Cryptography)0
8.1Secure Software Standard 8.1 (Activity Tracking)0
8.2Secure Software Standard 8.2 (Activity Tracking)0
8.3Secure Software Standard 8.3 (Activity Tracking)0
8.4Secure Software Standard 8.4 (Activity Tracking)0
9.1Secure Software Standard 9.1 (Attack Detection)0
A.1.1Secure Software Standard A.1.1 (Sensitive Authentication Data)0
A.2.1Secure Software Standard A.2.1 (Cardholder Data Protection)0
A.2.2Secure Software Standard A.2.2 (Cardholder Data Protection)0
A.2.3Secure Software Standard A.2.3 (Cardholder Data Protection)0
B.1.1Secure Software Standard B.1.1 (Terminal Software Documentation)0
B.1.2Secure Software Standard B.1.2 (Terminal Software Documentation)0
B.1.3Secure Software Standard B.1.3 (Terminal Software Documentation)0
B.2.1Secure Software Standard B.2.1 (Terminal Software Design)0
B.2.2Secure Software Standard B.2.2 (Terminal Software Design)0
B.2.3Secure Software Standard B.2.3 (Terminal Software Design)0
B.2.4Secure Software Standard B.2.4 (Terminal Software Design)0
B.2.5Secure Software Standard B.2.5 (Terminal Software Design)0
B.2.6Secure Software Standard B.2.6 (Terminal Software Design)0
B.2.7Secure Software Standard B.2.7 (Terminal Software Design)0
B.2.8Secure Software Standard B.2.8 (Terminal Software Design)0
B.2.9Secure Software Standard B.2.9 (Terminal Software Design)0
B.3.1Secure Software Standard B.3.1 (Terminal Software Attack Mitigation)0
B.3.2Secure Software Standard B.3.2 (Terminal Software Attack Mitigation)0
B.3.3Secure Software Standard B.3.3 (Terminal Software Attack Mitigation)0
B.4.1Secure Software Standard B.4.1 (Terminal Software Security Testing)0
B.5.1Secure Software Standard B.5.1 (Terminal Software Implementation Guidance)0
B.5.2Secure Software Standard B.5.2 (Terminal Software Implementation Guidance)0
C.1.1Secure Software Standard C.1.1 (Web Software Components & Services)0
C.1.2Secure Software Standard C.1.2 (Web Software Components & Services)0
C.1.3Secure Software Standard C.1.3 (Web Software Components & Services)0
C.1.4Secure Software Standard C.1.4 (Web Software Components & Services)0
C.1.5Secure Software Standard C.1.5 (Web Software Components & Services)0
C.1.6Secure Software Standard C.1.6 (Web Software Components & Services)0
C.1.7Secure Software Standard C.1.7 (Web Software Components & Services)0
C.2.1Secure Software Standard C.2.1 (Web Software Access Controls)0
C.2.2Secure Software Standard C.2.2 (Web Software Access Controls)0
C.2.3Secure Software Standard C.2.3 (Web Software Access Controls)0
C.3.1Secure Software Standard C.3.1 (Web Software Attack Mitigation)0
C.3.2Secure Software Standard C.3.2 (Web Software Attack Mitigation)0
C.3.3Secure Software Standard C.3.3 (Web Software Attack Mitigation)0
C.3.4Secure Software Standard C.3.4 (Web Software Attack Mitigation)0
C.3.5Secure Software Standard C.3.5 (Web Software Attack Mitigation)0
C.3.6Secure Software Standard C.3.6 (Web Software Attack Mitigation)0
C.4.1Secure Software Standard C.4.1 (Web Software Communications)0
CO-1Control Objective 1: Critical Asset Identification0
CO-10Control Objective 10: Threat and Vulnerability Management0
CO-11Control Objective 11: Secure Software Updates0
CO-12Control Objective 12: Software Vendor Implementation Guidance0
CO-2Control Objective 2: Secure Defaults0
CO-3Control Objective 3: Sensitive Data Retention0
CO-4Control Objective 4: Critical Asset Protection0
CO-5Control Objective 5: Authentication and Access Control0
CO-6Control Objective 6: Sensitive Data Protection0
CO-7Control Objective 7: Use of Cryptography0
CO-8Control Objective 8: Activity Tracking0
CO-9Control Objective 9: Attack Detection0
CO-A.1Control Objective A.1: Sensitive Authentication Data0
CO-A.2Control Objective A.2: Cardholder Data Protection0
CO-B.1Control Objective B.1: Terminal Software Documentation0
CO-B.2Control Objective B.2: Terminal Software Design0
CO-B.3Control Objective B.3: Terminal Software Attack Mitigation0
CO-B.4Control Objective B.4: Terminal Software Security Testing0
CO-B.5Control Objective B.5: Terminal Software Implementation Guidance0
CO-C.1Control Objective C.1: Web Software Components & Services0
CO-C.2Control Objective C.2: Web Software Access Controls0
CO-C.3Control Objective C.3: Web Software Attack Mitigation0
CO-C.4Control Objective C.4: Web Software Communications0
FRAMEWORKThe PCI Software Security Framework and its Secure Software Standard: what it is, its versions, and what is held0
MODULESHow the core requirements and Modules A, B and C apply to a given piece of software0
PROGRAMMEThe Secure Software Program: validation by an SSF assessor, the ROV and AOV, the listing, and the pending revision of v1.2.10
SEC-1Core section: Minimizing the Attack Surface0
SEC-10Core section: Secure Software Lifecycle Management0
SEC-4Core section: Software Protection Mechanisms0
SEC-8Core section: Secure Software Operations0
SECURE-SLCThe Secure Software Lifecycle Standard: the framework's second standard, not held, described from the programme guide and a 2019 practitioner guide0

Tell me when PCI SSF files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • TPSP register
  • AOC collection log
  • contractual responsibility matrix
  • monitoring cadence
  • vendor monitoring schedule
  • annual review reports
  • security charter
  • board reporting pack
  • risk register
  • policy library

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for PCI SSF, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition