Pci vs pii, explained in the register's terms; also phi pii pci, what is pci compliance manager

Updated

Pci vs pii is a phrase that gets searched by two people: the one who wants a definition for a memo and the one who has to sign an attestation about it next quarter. This page is written for the second. For a merchant or service provider that stores, processes or transmits cardholder data, pci vs pii comes down to a record and a set of figures: the record is the in-scope systems, the requirements assessed, the quarterly scans and the evidence behind each control, kept with an owner, a date and a status; the figures are the evidence load that record puts on its reviewers, the days an audit of it takes, the gaps an audit will find and what they cost, the incidents and cases it produces, and the training it requires. The sections below explain pci vs pii in those terms, say what it is not, and show where the free sheets on this site work each figure from the programme's own numbers with no account.

Why the search is pci vs pii

The words in pci vs pii are the words a merchant or service provider that stores, processes or transmits cardholder data uses when the obligation has a name and the programme does not yet have a number. The name is the regulator's, linked below; the number is the programme's own, and it is the count of obligations, controls and evidence items behind PCI DSS turned into reviewer hours on the obligations register sheet and into audit days on the audit scope sheet. A programme that searches pci vs pii and comes away with those two figures has done the first day of the work, and the paid plan on this site keeps what follows: the record, with owners, dates and the attestation that closes each period.

What pci vs pii means in practice

For a merchant or service provider that stores, processes or transmits cardholder data, it means being able to show, for each obligation, which control satisfies it, what evidence proves the control operated, who reviewed the evidence and who attested to the result. The record is the in-scope systems, the requirements assessed, the quarterly scans and the evidence behind each control. The regulator's own material, linked below, says what the obligations are; this site publishes none of that and no legal advice. What it publishes is the arithmetic: the obligations register sheet turns the count of obligations, controls and evidence items into reviewer hours and the months to a full attestation.

The searches this page answers, in the words people use

Measured in the United States, the phrasings that lead here are pci vs pii (150/mo), phi pii pci (100/mo), what is pci compliance manager (100/mo). They are one question asked 3 ways: a merchant or service provider that stores, processes or transmits cardholder data wants to know what the record must hold and what it costs to keep, and the PCI scope sheet on this site works the figure that answers it. The wording differs; the register behind it does not, and neither does the arithmetic.

The figures behind pci vs pii

Evidence items and reviewer hours; audit samples, days and coverage; expected gaps, remediation hours and cost; incident hours; case backlog months; training seats outstanding. Each is a free sheet on this site and each computes from the programme's own inputs. For PCI DSS the sheet to start with is the PCI scope sheet, which works the figure a merchant or service provider that stores, processes or transmits cardholder data is examined on first. A programme that knows those numbers has stopped estimating its own compliance.

What pci vs pii is not

It is not a certificate, a piece of software or a consultant's memo, although all three are sold under the name. It is a record and the figures that follow from it, kept by the business that owes the obligations. The guide this page supports covers the questions for a regulatory compliance consultant, the help a small business buys around that record. Attestvio Pro keeps the record at one flat price; the sheets are free with no account.

Questions people ask about pci vs pii

What is pci vs pii?

For a merchant or service provider that stores, processes or transmits cardholder data: keeping the in-scope systems, the requirements assessed, the quarterly scans and the evidence behind each control as a record with an owner, a date and a status, and being able to show for each obligation the control, the evidence and the attestation. The regulator's own material, linked below, defines the obligations; the free sheets on this site work the arithmetic.

Who is responsible for pci vs pii in a small business?

The compliance officer, or the owner wearing that hat, who signs the attestation. The sheets on this site are written for that person and need no account.

Does Attestvio make a business compliant with PCI DSS?

No. The business meets the obligations; Attestvio keeps the record and works the figures, and publishes no rule and no advice. Counsel and the regulator's own material say what the obligations are.

Sources

Related answers

Start Attestvio ProGet Attestvio Pro, $29 a month