Skip to content

Lab 02 — PCI Gap Assessment

Item Details
Lab 02 — PCI Gap Assessment
Module PCI DSS v4.x
Difficulty Intermediate
Estimated Time 120–150 Minutes
Primary Role PCI GRC Analyst
Supporting Roles Security, IAM, Network, Cloud, DevOps, Application Security, SOC, Third-Party Risk
Primary Objective Perform a structured PCI DSS readiness and gap assessment
Primary Output PCI Gap Assessment & Remediation Package

You previously completed:

Lab 01 — Build PCI Scope

for the fictional company:

CloudShop

The organization now has a documented PCI scope.

Management wants to know:

Are we actually ready for a PCI DSS assessment?

You have been assigned to perform a readiness review across the highest-risk areas of the environment.

During the assessment, you will discover deliberate weaknesses involving:

Network Segmentation
Access Control
MFA
Vulnerability Management
Secure Configuration
Logging & Monitoring
Penetration Testing
Third-Party Assurance

Your responsibility is not simply to identify issues.

You must determine:

What requirement area is affected?
What evidence should exist?
What evidence actually exists?
What is the control gap?
What is the security risk?
What caused the issue?
What should be fixed immediately?
What prevents recurrence?
Is CloudShop ready for formal PCI validation?

Build a complete PCI gap assessment that moves through:

PCI Scope
Requirement Area
Expected Control
Evidence
Observed Condition
Gap
Risk
Root Cause
Remediation
Retesting
Readiness Decision

By the end of the lab, you will create:

01 PCI Requirement Assessment Matrix
02 PCI Evidence Request Register
03 PCI Evidence Review Register
04 PCI Gap Register
05 PCI Risk Rating Matrix
06 PCI Root Cause Register
07 PCI Remediation Tracker
08 PCI Retest Register
09 PCI Readiness Dashboard
10 Executive PCI Gap Assessment Report

Use the scoped environment from Lab 01.

Payment Website
Payment API
Payment Database
Payment Database Backup
Jump Host
Enterprise Identity Provider
SIEM
Vulnerability Scanner
CI/CD Platform
Source Repository
Segmentation Firewall
Relevant Cloud Infrastructure
Cloud Provider
Payment Gateway
Payment Processor

Start by identifying the PCI areas you will assess.

For this lab, assess:

01 Network Security & Segmentation
02 Access Control
03 Authentication & MFA
04 Vulnerability Management
05 Secure Configuration
06 Logging & Monitoring
07 Penetration Testing
08 Third-Party Assurance

Step 1 — Build PCI Requirement Assessment Matrix

Section titled “Step 1 — Build PCI Requirement Assessment Matrix”

Create:

01 PCI Requirement Assessment Matrix

Use:

Area Expected Control Owner Evidence Status

Example:

Area Expected Control Owner Evidence Status
Segmentation Corporate networks isolated from CDE Network Firewall rules / test Pending
MFA Applicable CDE access protected by MFA IAM MFA report Pending
Vulnerability Critical findings remediated Security Scanner report Pending
Logging CDE systems centrally logged SOC SIEM inventory Pending

Step 2 — Build Evidence Request Register

Section titled “Step 2 — Build Evidence Request Register”

Create:

02 PCI Evidence Request Register

Request the following evidence.

Current Network Diagram
CDE Firewall Rule Export
CDE Communication Matrix
Segmentation Test Results
CDE User Population
Privileged User Population
MFA Coverage Report
Quarterly Access Review
Termination Records
CDE Scan Report
Critical / High Vulnerability Register
Patch Compliance Report
ASV Reports
Risk Exceptions
CDE Hardening Baseline
Configuration Compliance Report
Cloud Security Group Review
Configuration Exceptions
CDE Log Source Inventory
SIEM Coverage Report
Log Review Evidence
Retention Configuration
Time Synchronization Evidence
Latest Penetration Test
Segmentation Test
Finding Remediation
Retest Evidence
Cloud Provider AOC
Payment Gateway AOC
Payment Processor Assurance
Responsibility Matrix

Use:

Request ID Evidence Owner Due Status

Use:

Relevant?
Reliable?
Complete?
Current?
Correct Scope?
Correct Period?

Create:

03 PCI Evidence Review Register

Use:

Evidence Expected Received Quality Result

Scenario Finding 1 — Segmentation Failure

Section titled “Scenario Finding 1 — Segmentation Failure”

Network documentation states:

Developer Network
CDE

But technical testing shows:

Developer Network
Payment Database
TCP/5432

is reachable.

Out-of-Scope Network
Blocked From CDE
Developer Network
CDE Database
Segmentation Failure

A compromised developer workstation may provide an unauthorized path into the CDE.

Potential impact:

CDE Compromise
Scope Expansion
Cardholder Data Exposure
Critical

or High depending on the complete environment and exploitability.

Create entry:

Gap ID Area Condition Severity Owner
PCI-GAP-001 Segmentation Developer network can reach payment DB Critical Network

Scenario Finding 2 — Excessive Privileged Access

Section titled “Scenario Finding 2 — Excessive Privileged Access”

IAM report shows:

CDE Administrators:
18

Review identifies:

4 Developers

with permanent:

Database Administrator

access.

Interviews confirm they only require application deployment access.

Least Privilege
Excessive DBA Access
Access Control Failure

Developers may:

Read Payment Data
Modify Database Configuration
Alter Payment Records
High

IAM evidence shows:

Privileged CDE Identities:
22

MFA enabled:

20

Two local administrator accounts are excluded from centralized MFA.

Applicable Privileged CDE Access
MFA
2 Local Administrators
Without MFA
Authentication Control Failure
High

Scenario Finding 4 — Delayed Termination

Section titled “Scenario Finding 4 — Delayed Termination”

Termination sample:

20 Users Tested

Results:

18 Disabled Within Required Process
2 Contractor Accounts
Remained Active 6 Days

Former contractors retained CDE access.

Identity Lifecycle Failure
High

Scenario Finding 5 — Critical Vulnerability Overdue

Section titled “Scenario Finding 5 — Critical Vulnerability Overdue”

Vulnerability report shows:

Internet-Facing Payment API

has:

Critical Remote Code Execution Vulnerability

Age:

42 Days

No:

Approved Risk Exception

exists.

Critical Vulnerability
Timely Remediation
42 Days Open
Critical

Review:

Q1 → Pass
Q2 → Pass
Q3 → Fail
Q4 → Pass

For Q3:

No Passing Rescan

exists.

Incomplete External Vulnerability Validation
High

One payment application server runs:

Unsupported Operating System

Vendor security patches are no longer available.

No formal:

Migration Plan

or:

Risk Exception

exists.

New vulnerabilities may remain permanently unpatched.

High

Scenario Finding 8 — Secure Configuration Failure

Section titled “Scenario Finding 8 — Secure Configuration Failure”

Cloud security group configuration:

0.0.0.0/0
TCP/22
Payment Web Server
Administrative Access
Restricted Source
SSH Accessible From Internet
Critical

Scenario Finding 9 — Logging Coverage Gap

Section titled “Scenario Finding 9 — Logging Coverage Gap”

CDE asset inventory:

35 Systems

SIEM coverage:

32 Systems

Missing:

2 Payment Application Servers
1 Database Server
Incomplete CDE Logging Coverage
High

Scenario Finding 10 — Insufficient Log Retention

Section titled “Scenario Finding 10 — Insufficient Log Retention”

Database audit logs are retained for:

60 Days

while the approved PCI logging design requires:

12 Months

with the applicable recent period immediately available.

Log Retention Failure
High

Application logs contain:

PAN=4111111111111111

These logs are sent to the SIEM.

Unnecessary CHD Storage
Scope Expansion
Increased Breach Impact
Critical

Expected:

Daily Security Review

Evidence shows:

14 Days

during the assessment period without review evidence.

Recurring Monitoring Control Failure
High

Scenario Finding 13 — Penetration Test Finding Not Retested

Section titled “Scenario Finding 13 — Penetration Test Finding Not Retested”

Penetration test identified:

High-Risk Authorization Bypass

Engineering marked:

Fixed

but no:

Retest Evidence

exists.

Remediation Not Validated
High

Scenario Finding 14 — Segmentation Test Outdated

Section titled “Scenario Finding 14 — Segmentation Test Outdated”

Latest segmentation test:

14 Months Ago

Since then CloudShop implemented:

New Transit Gateway
New Developer Network
New CDE Route

No post-change test exists.

Segmentation Assurance Outdated
High

Scenario Finding 15 — Expired Provider Assurance

Section titled “Scenario Finding 15 — Expired Provider Assurance”

Payment Gateway:

Current PCI AOC

Cloud Provider:

Current PCI AOC

Payment Processor:

AOC Expired 9 Months Ago

No updated assurance is available.

Third-Party Assurance Failure
High

Scenario Finding 16 — Responsibility Matrix Missing

Section titled “Scenario Finding 16 — Responsibility Matrix Missing”

CloudShop uses multiple service providers, but no formal matrix documents:

Merchant Responsibility
Cloud Provider Responsibility
Payment Provider Responsibility

Controls may:

Be Duplicated
Be Assumed
Be Completely Missed
Medium / High

Create:

04 PCI Gap Register

Use:

ID Area Gap Severity Owner Status

Example entries:

ID Area Gap Severity
PCI-GAP-001 Segmentation Developer network reaches payment DB Critical
PCI-GAP-002 Access Developers have unnecessary DBA High
PCI-GAP-003 MFA 2 privileged accounts without MFA High
PCI-GAP-004 IAM Contractor termination delayed High
PCI-GAP-005 Vulnerability Critical RCE overdue Critical
PCI-GAP-006 ASV Q3 no passing rescan High
PCI-GAP-007 Technology Unsupported CDE OS High
PCI-GAP-008 Configuration Public SSH on payment server Critical
PCI-GAP-009 Logging 3 CDE systems missing from SIEM High
PCI-GAP-010 Logging Database logs retained 60 days High
PCI-GAP-011 Data Protection PAN stored in logs Critical
PCI-GAP-012 Monitoring Daily review missing High
PCI-GAP-013 Pen Test Finding not retested High
PCI-GAP-014 Segmentation Testing outdated after change High
PCI-GAP-015 Third Party Processor AOC expired High
PCI-GAP-016 Third Party Responsibility matrix absent Medium

Create:

05 PCI Risk Rating Matrix

Use two dimensions:

Likelihood
Impact

Example:

Likelihood Impact Rating
High High Critical
Medium High High
High Medium High
Medium Medium Medium
Low Low Low

Consider:

Internet Exposure
CDE Access
Privilege
Cardholder Data Exposure
Exploitability
Control Failure Duration
Existing Mitigation

Condition:

Internet
SSH
Payment Server

Likelihood:

High

Impact:

High

Risk:

Critical

Example Risk Analysis — Responsibility Matrix

Section titled “Example Risk Analysis — Responsibility Matrix”

Condition:

Shared Responsibilities
Not Documented

Likelihood:

Medium

Impact:

Medium / High

Risk:

Medium / High

Create:

06 PCI Root Cause Register

Use:

Gap Immediate Cause Root Cause Preventive Action

Immediate cause:

Firewall Rule Allows Developer CIDR

Investigation:

Temporary Troubleshooting Rule
No Expiry
Never Removed

Root cause:

Temporary CDE firewall rules do not have enforced expiration or recurring review.

Immediate cause:

Developers Retained Legacy Access

Root cause:

Role changes do not trigger automatic CDE entitlement recertification.

Immediate cause:

Local Accounts Outside IdP

Root cause:

Local administrative accounts are excluded from centralized identity-governance controls.

Immediate cause:

Contractors Missing From HR Feed

Root cause:

Contractor lifecycle management is not integrated with IAM deprovisioning.

Immediate cause:

Patch Ticket Not Escalated

Root cause:

Critical vulnerability SLA monitoring lacks management escalation.

Immediate cause:

Application Logs Entire Request Body

Root cause:

Secure development standards do not explicitly prohibit payment-data logging and automated detection is absent.

Immediate cause:

New Servers Missing SIEM Agent

Root cause:

Central logging is not enforced through the approved server deployment baseline.

Immediate cause:

AOC Expiry Not Tracked

Root cause:

PCI service-provider assurance is not integrated into the recurring third-party review calendar.

Phase 7 — Define Correction and Corrective Action

Section titled “Phase 7 — Define Correction and Corrective Action”

For every gap distinguish:

Correction

from:

Corrective Action

Correction:

Remove Public SSH Rule

Corrective action:

Implement Policy-as-Code
Blocking Public CDE Admin Ports

Correction:

Enable MFA on 2 Accounts

Corrective action:

Integrate Local Admin Accounts
Into MFA Coverage Monitoring

Correction:

Stop PAN Logging

Corrective action:

Update Secure Logging Standard
Add PAN Redaction
Implement Automated Detection
Review Historical Logs

Create:

07 PCI Remediation Tracker

Use:

Gap Correction Corrective Action Owner Due Status
PCI-GAP-001
Segmentation Failure
PCI-GAP-005
Critical RCE
PCI-GAP-008
Public SSH
PCI-GAP-011
PAN in Logs
MFA Gaps
Excessive Privilege
Termination Failure
ASV Failure
Logging Coverage
Retention
Pen Test Retest
Outdated Segmentation Test
Expired Provider AOC
Remove Developer-to-DB Rule
Review All CDE Firewall Rules
Retest Segmentation
Reassess PCI Scope
Remove Developer DBA Rights
Perform Complete Privileged Access Review
Implement Role-Based Entitlements
Enable MFA
Inventory Local Accounts
Monitor MFA Coverage
Disable Remaining Accounts
Integrate Contractor Lifecycle
Monitor Deprovisioning SLA
Patch Critical RCE
Run Vulnerability Rescan
Implement SLA Escalation
Review Q3 Failure
Validate Remediation
Document Historical Gap
Maintain Passing Future Scans
Isolate Legacy Server
Create Migration Project
Apply Enhanced Monitoring
Approve Time-Bound Risk Exception
Deploy Missing Log Agents
Validate SIEM Ingestion
Extend Retention
Implement Missing-Source Alerts
Stop Logging PAN
Identify Historical PAN
Secure / Remove Data
Review Scope Impact
Implement Redaction
Perform Retest
Close Only After Pass
Request Updated Processor AOC
Validate Service Scope
Create Responsibility Matrix

Do not close findings based on:

Owner Says Fixed

Use:

Correction
Evidence
Retest
Pass / Fail

Create:

08 PCI Retest Register

Use:

Gap Retest Method Expected Actual Result

Test:

Developer Network
Payment Database

Expected:

Blocked

Test:

Internet
Payment Server
22

Expected:

Blocked

Population:

All Privileged CDE Accounts

Expected:

100% MFA Coverage

Reconcile:

CDE Asset Inventory
SIEM Log Sources

Expected:

100% Required Coverage

Rescan:

Payment API

Expected:

Critical RCE
No Longer Present

Attempt original authorization-bypass attack.

Expected:

Access Denied

Create:

09 PCI Readiness Dashboard

Suggested metrics:

Metric Current Target
CDE Scope Accuracy 90% 100%
MFA Coverage 91% 100%
Logging Coverage 91% 100%
Critical Findings Open 4 0
High Findings Open 11 0
Passing Required ASV Results Incomplete Complete
Current Provider Assurance 67% 100%
Segmentation Validation Failed Passed

Use:

Green
→ Ready
Amber
→ Conditional Readiness
Red
→ Not Ready

Current CloudShop status:

RED

CloudShop currently has:

4 Critical Gaps
Multiple High Gaps
Failed Segmentation
Incomplete MFA
Critical Vulnerability
PAN in Logs
Missing Logging Coverage
Unvalidated Pen Test Remediation
Expired Provider Assurance

Recommended conclusion:

NOT READY
FOR FORMAL PCI VALIDATION

The organization has several material issues affecting:

PCI Scope
CDE Security
Authentication
Attack Surface
Audit Visibility
Testing Assurance
Third-Party Assurance

Formal validation should not proceed until material gaps are corrected and retested.

Phase 13 — Build Executive PCI Gap Assessment Report

Section titled “Phase 13 — Build Executive PCI Gap Assessment Report”

Create:

10 Executive PCI Gap Assessment Report

Use the following format.

CloudShop’s PCI readiness assessment identified significant security and compliance weaknesses across the current Cardholder Data Environment.

The assessment identified:

16 Total Findings
4 Critical
11 High
1 Medium

Key concerns include:

Failed Network Segmentation
Internet-Exposed Administrative Access
Overdue Critical Vulnerability
PAN Stored in Security Logs
Incomplete MFA
Incomplete Logging Coverage
Missing Penetration-Test Retest
Expired Third-Party PCI Assurance

Current readiness:

NOT READY
FOR FORMAL PCI DSS VALIDATION
Fix Segmentation
Remove Public Administration
Patch Critical Vulnerability
Remove PAN From Logs
100% MFA
Remove Excess Privilege
Fix Contractor Termination

Priority 3 — Restore Security Visibility

Section titled “Priority 3 — Restore Security Visibility”
Complete SIEM Coverage
Correct Log Retention
Restore Required Log Reviews
Retest Penetration Finding
Perform Updated Segmentation Test
Obtain Passing Required Scans

Priority 5 — Strengthen Provider Governance

Section titled “Priority 5 — Strengthen Provider Governance”
Obtain Current AOCs
Create PCI Responsibility Matrix
Track Provider Expiry

Management should delay final PCI validation until:

Critical Findings
0
High-Risk Material Findings
Remediated
Segmentation
Retested & Passed
MFA
100%
Logging
Complete
Critical Vulnerabilities
Closed
Pen Test Findings
Retested
Provider Assurance
Current
  • Current PCI scope reviewed.

  • CDE inventory reviewed.

  • security-impacting systems reviewed.

  • third parties reviewed.

  • segmentation assumptions tested.

  • firewall rules reviewed.

  • unauthorized CDE paths identified.

  • admin interfaces reviewed.

  • segmentation evidence validated.

  • user population reviewed.

  • privileged population reviewed.

  • excessive access identified.

  • termination sample tested.

  • third-party identities reviewed.

  • centralized identities reviewed.

  • local identities reviewed.

  • break-glass accounts reviewed.

  • MFA coverage calculated.

  • CDE scan coverage reviewed.

  • critical/high vulnerabilities assessed.

  • SLA compliance reviewed.

  • ASV status reviewed.

  • unsupported technologies reviewed.

  • hardening standards reviewed.

  • public admin ports reviewed.

  • exceptions reviewed.

  • configuration drift reviewed.

  • CDE logging coverage reconciled.

  • retention reviewed.

  • daily reviews reviewed.

  • missing log sources identified.

  • PAN / sensitive data in logs assessed.

  • penetration test reviewed.

  • findings reviewed.

  • retest evidence reviewed.

  • segmentation testing reviewed.

  • significant changes considered.

  • provider list reviewed.

  • AOCs reviewed.

  • assurance periods validated.

  • responsibility matrix reviewed.

  • expired assurance escalated.

  • gaps documented.

  • severity assigned.

  • owners assigned.

  • root causes documented.

  • corrections defined.

  • corrective actions defined.

  • retesting planned.

IAM report says:

100% MFA

During server review you discover:

local-admin

with no MFA.

Question:

Is the IAM report sufficient evidence?

Answer:

No

The population was incomplete.

Network team says:

All Firewall Rules Reviewed

But penetration testing shows:

Developer Network
Payment Database

Question:

Is the firewall-review control effective?

Answer:

Not fully

The review failed to detect or remediate a material rule.

Challenge 3 — Engineer Says Vulnerability Is Fixed

Section titled “Challenge 3 — Engineer Says Vulnerability Is Fixed”

Engineer states:

RCE Fixed Yesterday

Question:

Can the gap be closed?

Answer:

No

Perform a rescan or appropriate technical validation.

Challenge 4 — Provider Website Says “PCI Compliant”

Section titled “Challenge 4 — Provider Website Says “PCI Compliant””

Payment processor website displays:

PCI DSS Compliant

but no current AOC is available.

Question:

Is this sufficient assurance?

Answer:

No

Obtain and validate appropriate current assurance.

Engineering stops new PAN logging today.

Question:

Is the finding immediately closed?

Answer:

No

You must assess:

Historical Logs
Retention
Scope
Data Removal / Protection
Root Cause
Preventive Control

Before completing the lab, confirm you created:

  • 01 PCI Requirement Assessment Matrix

  • 02 PCI Evidence Request Register

  • 03 PCI Evidence Review Register

  • 04 PCI Gap Register

  • 05 PCI Risk Rating Matrix

  • 06 PCI Root Cause Register

  • 07 PCI Remediation Tracker

  • 08 PCI Retest Register

  • 09 PCI Readiness Dashboard

  • 10 Executive PCI Gap Assessment Report

The mission is complete when you can answer:

Which PCI controls are working?
Which controls are failing?
Which evidence is incomplete?
Which gaps affect PCI scope?
Which gaps present direct security risk?
Which gaps are systemic?
What caused each major finding?
What must be fixed immediately?
What corrective action prevents recurrence?
How will remediation be retested?
Is the organization ready for formal PCI validation?

Your final PCI Gap Assessment Package should contain:

Executive Summary
Assessment Scope
Requirement Assessment Matrix
Evidence Register
Gap Register
Risk Ratings
Root Cause Analysis
Remediation Plan
Retest Plan
Readiness Dashboard
Final Readiness Conclusion

The package should be suitable for review by:

PCI Program Owner
CISO
GRC
Security Architecture
IAM
Network Security
Cloud Security
Payment Engineering
Internal Audit
QSA / PCI Assessor

You have now completed:

You moved from:

PCI Scope

to:

Control Expectations
Evidence Review
Technical Validation
Gap Identification
Risk Assessment
Root Cause
Remediation
Retesting
Readiness Decision

The key lesson from this lab is:

PCI readiness is not determined by how many policies exist. It is determined by whether the complete in-scope environment is protected by controls that operate consistently and can be demonstrated through reliable evidence.

➡️ Next: Runbook 01 — PCI DSS Assessment & Evidence Collection

In the first operational runbook for this module, you will convert the concepts from both PCI labs into a repeatable enterprise process for managing PCI assessments.

The runbook will cover:

Assessment Initiation
Scope Confirmation
Requirement Applicability
Control Ownership
Evidence Requests
Population Validation
Walkthroughs
Control Testing
Gap Management
Remediation
Retesting
Assessment Coordination

The goal will be to create a repeatable process a GRC Analyst can execute during every PCI assessment cycle.