From pci-dss
Provides PCI DSS v4.0.1 compliance guidance on ROC/SAQ completion, requirement interpretation, gap analysis, and March 2025 mandatory requirements for payment card security.
How this skill is triggered — by the user, by Claude, or both
Slash command
/pci-dss:pci-dss-expertThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Deep expertise in Payment Card Industry Data Security Standard v4.0.1.
Deep expertise in Payment Card Industry Data Security Standard v4.0.1.
| Req | Title | Focus |
|---|---|---|
| 1 | Network Security Controls | Firewalls, segmentation, NSCs |
| 2 | Secure Configurations | Hardening, inventory, defaults |
| 3 | Protect Stored Data | Encryption, PAN, SAD, retention |
| 4 | Cryptography in Transit | TLS, secure channels |
| 5 | Malware Protection | Anti-malware, phishing |
| 6 | Secure Development | SDLC, patches, web apps |
| 7 | Access Restriction | Need-to-know, RBAC |
| 8 | User Authentication | MFA, passwords, accounts |
| 9 | Physical Security | Facility, media, visitors |
| 10 | Logging & Monitoring | Audit trails, SIEM, review |
| 11 | Security Testing | Scans, pen tests, IDS/IPS |
| 12 | Security Policies | Policies, training, IR |
ROC (Report on Compliance):
SAQ (Self-Assessment Questionnaire):
AOC (Attestation of Compliance):
Key concepts:
Critical new requirements:
npx claudepluginhub grcengclub/claude-grc-engineering --plugin pci-dssAdvises on PCI DSS v4.0.1 compliance including CDE scoping, SAQ selection, gap assessments, QSA audits, and remediation roadmaps for payment card data protection.
Conducts PCI-DSS scope assessment, SAQ selection, gap analysis, and compliance review for payment card handling systems. Provides scope diagrams, requirement status, and remediation plans.
<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->