Due to the variance between companies, we suggest the following “Common Denominator” Validation Process:
---
Scoping+Sampling – determine what system components are governed by PCI DSS
Complete an annual Self-Assessment Questionnaire (different types as a function of size, activity and risk).
In some cases it is required to carry out a yearly audit on-site by a Qualified Security Assessor
Secure publicly facing web applications (PCI Requirement 6.6)
Document and submit proof of compliance to acquiring banks
---