Security Questionnaire Mapper
Customer type

What a card merchant or payment processor's security questionnaire reaches for

Card merchants ask whether account data passes through the service and for the PCI DSS attestation that covers it, then the requirements that attestation rests on.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), PCI DSS v4.0.1 and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Information security policySOC 2 CC5.3
Risk assessmentSOC 2 CC3.2
Independent audit and certificationSOC 2 CC4.1
Multi-factor authenticationSOC 2 CC6.1 · PCI DSS 8.4.2
Password policySOC 2 CC6.1
Access provisioning and reviewSOC 2 CC6.2 · PCI DSS 7.2.4
Encryption at restSOC 2 CC6.1 · PCI DSS 3.5.1 · GDPR Art. 32
Encryption in transitPCI DSS 4.2.1
Data retention and secure deletionPCI DSS 3.2.1 · GDPR Art. 28
Data location and transfersGDPR Art. 44 · GDPR Art. 46
Cardholder data and PCI DSSno ISO 27001 clause: beyond an ISO 27001 certificatePCI DSS 3.2.1 · PCI DSS 12.5.2
Logging and monitoringSOC 2 CC7.2 · PCI DSS 10.4.1
Vulnerability and patch managementSOC 2 CC7.1 · PCI DSS 6.3.3 · PCI DSS 11.3.1
Penetration testingPCI DSS 11.4.3
Secure development and changeSOC 2 CC8.1
Incident response planSOC 2 CC7.4 · PCI DSS 12.10.1
Notifying the customer of an incidentSOC 2 CC7.4 · GDPR Art. 33
Business continuity planSOC 2 A1.3
Backup and disaster recoverySOC 2 A1.2
Subcontractors and subprocessorsSOC 2 CC9.2 · PCI DSS 12.8.1 · GDPR Art. 28
Assessing your own suppliersSOC 2 CC9.2
Data subject requestsGDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeGDPR Art. 6
Data processing agreementGDPR Art. 28