PCI-SSF-01 | Information security program management | 0 |
PCI-SSF-02 | Board and management oversight | 0 |
PCI-SSF-03 | Risk appetite and tolerance for IT risk | 55 |
PCI-SSF-04 | Security policy framework | 0 |
PCI-SSF-05 | Roles and responsibilities definition | 110 |
PCI-SSF-06 | Network security and segmentation | 31 |
PCI-SSF-07 | Endpoint protection and detection | 10 |
PCI-SSF-08 | Application security controls | 26 |
PCI-SSF-09 | Encryption and key management | 62 |
PCI-SSF-10 | Secure configuration standards | 32 |
PCI-SSF-11 | Business continuity planning and testing | 21 |
PCI-SSF-12 | Disaster recovery procedures | 66 |
PCI-SSF-13 | Third-party dependency management | 0 |
PCI-SSF-14 | Critical service identification | 32 |
PCI-SSF-15 | Communication and escalation procedures | 45 |
PCI-SSF-16 | Due diligence and onboarding | 56 |
PCI-SSF-17 | Contractual security requirements | 55 |
PCI-SSF-18 | Ongoing monitoring and assessment | 0 |
PCI-SSF-19 | Concentration risk management | 0 |
PCI-SSF-20 | Exit strategy and transition planning | 0 |
PCI-SSF-21 | Incident detection and classification | 72 |
PCI-SSF-22 | Incident response and containment | 0 |
PCI-SSF-23 | Regulatory reporting requirements | 0 |
PCI-SSF-24 | Customer notification procedures | 72 |
PCI-SSF-25 | Post-incident review and improvement | 72 |
SSLC-1.1 | Security Responsibility and Resources | 0 |
SSLC-10.1 | Software Integrity | 0 |
SSLC-11.1 | Stakeholder Communication | 0 |
SSLC-12.1 | Software Update Integrity and Verification | 0 |
SSLC-2.1 | Software Security Policy | 0 |
SSLC-3.1 | Software Security Personnel Skills | 0 |
SSLC-4.1 | Threat Identification and Risk Mitigation | 0 |
SSLC-5.1 | Software Design Security | 0 |
SSLC-6.1 | Secure Coding Practices | 1 |
SSLC-7.1 | Security Testing | 1 |
SSLC-8.1 | Vulnerability Disclosure and Response | 0 |
SSLC-9.1 | Change Management | 4 |
SSS-1.1 | Critical Asset Identification | 0 |
SSS-1.2 | Critical Asset Protection | 0 |
SSS-10.1 | Sensitive Authentication Data (Module A) | 0 |
SSS-11.1 | Terminal Software Module Requirements (Module B) | 0 |
SSS-2.1 | Sensitive Data Inventory and Protection | 0 |
SSS-3.1 | Critical Asset Cryptographic Protection | 0 |
SSS-4.1 | Authentication and Access Control | 0 |
SSS-5.1 | Attack Detection | 0 |
SSS-6.1 | Threat and Vulnerability Management | 0 |
SSS-7.1 | Secure Software Updates | 0 |
SSS-8.1 | Vendor Security Guidance | 0 |
SSS-9.1 | Account-Data Protection (Module A) | 0 |
1.1 | Secure Software Standard 1.1 (Critical Asset Identification) | 0 |
1.2 | Secure Software Standard 1.2 (Critical Asset Identification) | 0 |
1.3 | Secure Software Standard 1.3 (Critical Asset Identification) | 0 |
10.1 | Secure Software Standard 10.1 (Threat and Vulnerability Management) | 0 |
10.2 | Secure Software Standard 10.2 (Threat and Vulnerability Management) | 0 |
11.1 | Secure Software Standard 11.1 (Secure Software Updates) | 0 |
11.2 | Secure Software Standard 11.2 (Secure Software Updates) | 0 |
12.1 | Secure Software Standard 12.1 (Software Vendor Implementation Guidance) | 0 |
2.1 | Secure Software Standard 2.1 (Secure Defaults) | 0 |
2.2 | Secure Software Standard 2.2 (Secure Defaults) | 0 |
2.3 | Secure Software Standard 2.3 (Secure Defaults) | 0 |
2.4 | Secure Software Standard 2.4 (Secure Defaults) | 0 |
2.5 | Secure Software Standard 2.5 (Secure Defaults) | 0 |
3.1 | Secure Software Standard 3.1 (Sensitive Data Retention) | 0 |
3.2 | Secure Software Standard 3.2 (Sensitive Data Retention) | 0 |
3.3 | Secure Software Standard 3.3 (Sensitive Data Retention) | 0 |
3.4 | Secure Software Standard 3.4 (Sensitive Data Retention) | 0 |
3.5 | Secure Software Standard 3.5 (Sensitive Data Retention) | 0 |
3.6 | Secure Software Standard 3.6 (Sensitive Data Retention) | 0 |
4.1 | Secure Software Standard 4.1 (Critical Asset Protection) | 0 |
4.2 | Secure Software Standard 4.2 (Critical Asset Protection) | 0 |
5.1 | Secure Software Standard 5.1 (Authentication and Access Control) | 0 |
5.2 | Secure Software Standard 5.2 (Authentication and Access Control) | 0 |
5.3 | Secure Software Standard 5.3 (Authentication and Access Control) | 0 |
5.4 | Secure Software Standard 5.4 (Authentication and Access Control) | 0 |
6.1 | Secure Software Standard 6.1 (Sensitive Data Protection) | 0 |
6.2 | Secure Software Standard 6.2 (Sensitive Data Protection) | 0 |
6.3 | Secure Software Standard 6.3 (Sensitive Data Protection) | 0 |
7.1 | Secure Software Standard 7.1 (Use of Cryptography) | 0 |
7.2 | Secure Software Standard 7.2 (Use of Cryptography) | 0 |
7.3 | Secure Software Standard 7.3 (Use of Cryptography) | 0 |
7.4 | Secure Software Standard 7.4 (Use of Cryptography) | 0 |
8.1 | Secure Software Standard 8.1 (Activity Tracking) | 0 |
8.2 | Secure Software Standard 8.2 (Activity Tracking) | 0 |
8.3 | Secure Software Standard 8.3 (Activity Tracking) | 0 |
8.4 | Secure Software Standard 8.4 (Activity Tracking) | 0 |
9.1 | Secure Software Standard 9.1 (Attack Detection) | 0 |
A.1.1 | Secure Software Standard A.1.1 (Sensitive Authentication Data) | 0 |
A.2.1 | Secure Software Standard A.2.1 (Cardholder Data Protection) | 0 |
A.2.2 | Secure Software Standard A.2.2 (Cardholder Data Protection) | 0 |
A.2.3 | Secure Software Standard A.2.3 (Cardholder Data Protection) | 0 |
B.1.1 | Secure Software Standard B.1.1 (Terminal Software Documentation) | 0 |
B.1.2 | Secure Software Standard B.1.2 (Terminal Software Documentation) | 0 |
B.1.3 | Secure Software Standard B.1.3 (Terminal Software Documentation) | 0 |
B.2.1 | Secure Software Standard B.2.1 (Terminal Software Design) | 0 |
B.2.2 | Secure Software Standard B.2.2 (Terminal Software Design) | 0 |
B.2.3 | Secure Software Standard B.2.3 (Terminal Software Design) | 0 |
B.2.4 | Secure Software Standard B.2.4 (Terminal Software Design) | 0 |
B.2.5 | Secure Software Standard B.2.5 (Terminal Software Design) | 0 |
B.2.6 | Secure Software Standard B.2.6 (Terminal Software Design) | 0 |
B.2.7 | Secure Software Standard B.2.7 (Terminal Software Design) | 0 |
B.2.8 | Secure Software Standard B.2.8 (Terminal Software Design) | 0 |
B.2.9 | Secure Software Standard B.2.9 (Terminal Software Design) | 0 |
B.3.1 | Secure Software Standard B.3.1 (Terminal Software Attack Mitigation) | 0 |
B.3.2 | Secure Software Standard B.3.2 (Terminal Software Attack Mitigation) | 0 |
B.3.3 | Secure Software Standard B.3.3 (Terminal Software Attack Mitigation) | 0 |
B.4.1 | Secure Software Standard B.4.1 (Terminal Software Security Testing) | 0 |
B.5.1 | Secure Software Standard B.5.1 (Terminal Software Implementation Guidance) | 0 |
B.5.2 | Secure Software Standard B.5.2 (Terminal Software Implementation Guidance) | 0 |
C.1.1 | Secure Software Standard C.1.1 (Web Software Components & Services) | 0 |
C.1.2 | Secure Software Standard C.1.2 (Web Software Components & Services) | 0 |
C.1.3 | Secure Software Standard C.1.3 (Web Software Components & Services) | 0 |
C.1.4 | Secure Software Standard C.1.4 (Web Software Components & Services) | 0 |
C.1.5 | Secure Software Standard C.1.5 (Web Software Components & Services) | 0 |
C.1.6 | Secure Software Standard C.1.6 (Web Software Components & Services) | 0 |
C.1.7 | Secure Software Standard C.1.7 (Web Software Components & Services) | 0 |
C.2.1 | Secure Software Standard C.2.1 (Web Software Access Controls) | 0 |
C.2.2 | Secure Software Standard C.2.2 (Web Software Access Controls) | 0 |
C.2.3 | Secure Software Standard C.2.3 (Web Software Access Controls) | 0 |
C.3.1 | Secure Software Standard C.3.1 (Web Software Attack Mitigation) | 0 |
C.3.2 | Secure Software Standard C.3.2 (Web Software Attack Mitigation) | 0 |
C.3.3 | Secure Software Standard C.3.3 (Web Software Attack Mitigation) | 0 |
C.3.4 | Secure Software Standard C.3.4 (Web Software Attack Mitigation) | 0 |
C.3.5 | Secure Software Standard C.3.5 (Web Software Attack Mitigation) | 0 |
C.3.6 | Secure Software Standard C.3.6 (Web Software Attack Mitigation) | 0 |
C.4.1 | Secure Software Standard C.4.1 (Web Software Communications) | 0 |
CO-1 | Control Objective 1: Critical Asset Identification | 0 |
CO-10 | Control Objective 10: Threat and Vulnerability Management | 0 |
CO-11 | Control Objective 11: Secure Software Updates | 0 |
CO-12 | Control Objective 12: Software Vendor Implementation Guidance | 0 |
CO-2 | Control Objective 2: Secure Defaults | 0 |
CO-3 | Control Objective 3: Sensitive Data Retention | 0 |
CO-4 | Control Objective 4: Critical Asset Protection | 0 |
CO-5 | Control Objective 5: Authentication and Access Control | 0 |
CO-6 | Control Objective 6: Sensitive Data Protection | 0 |
CO-7 | Control Objective 7: Use of Cryptography | 0 |
CO-8 | Control Objective 8: Activity Tracking | 0 |
CO-9 | Control Objective 9: Attack Detection | 0 |
CO-A.1 | Control Objective A.1: Sensitive Authentication Data | 0 |
CO-A.2 | Control Objective A.2: Cardholder Data Protection | 0 |
CO-B.1 | Control Objective B.1: Terminal Software Documentation | 0 |
CO-B.2 | Control Objective B.2: Terminal Software Design | 0 |
CO-B.3 | Control Objective B.3: Terminal Software Attack Mitigation | 0 |
CO-B.4 | Control Objective B.4: Terminal Software Security Testing | 0 |
CO-B.5 | Control Objective B.5: Terminal Software Implementation Guidance | 0 |
CO-C.1 | Control Objective C.1: Web Software Components & Services | 0 |
CO-C.2 | Control Objective C.2: Web Software Access Controls | 0 |
CO-C.3 | Control Objective C.3: Web Software Attack Mitigation | 0 |
CO-C.4 | Control Objective C.4: Web Software Communications | 0 |
FRAMEWORK | The PCI Software Security Framework and its Secure Software Standard: what it is, its versions, and what is held | 0 |
MODULES | How the core requirements and Modules A, B and C apply to a given piece of software | 0 |
PROGRAMME | The Secure Software Program: validation by an SSF assessor, the ROV and AOV, the listing, and the pending revision of v1.2.1 | 0 |
SEC-1 | Core section: Minimizing the Attack Surface | 0 |
SEC-10 | Core section: Secure Software Lifecycle Management | 0 |
SEC-4 | Core section: Software Protection Mechanisms | 0 |
SEC-8 | Core section: Secure Software Operations | 0 |
SECURE-SLC | The Secure Software Lifecycle Standard: the framework's second standard, not held, described from the programme guide and a 2019 practitioner guide | 0 |