- Assessed Environment*
- Assessment Date*
- MFA enabled for admin access*
- Shared account use*
- Privileged access review frequency*
- TLS/HTTPS enforced for all connections?*
- API keys and tokens stored securely?*
- Only the last 4 digits of payment data visible in logs and screens?*
- API authentication method*
- Webhook signature verification enabled*
- IP allowlisting or source validation in place*
- Rate limiting or throttling configured*
- Versioning and change control for API integrations*
- Security logs retained per policy?*
- Administrative actions logged?*
- Transaction anomalies logged?*
- Alerts configured for suspicious activity?*
- Log access restricted to authorized personnel?*
- Velocity checks implemented*
- Anomaly detection in place*
- Chargeback monitoring enabled*
- Manual review for high-risk transactions*
- Card verification support enabled*
- 3-D Secure or equivalent step-up verification used*
- Approval and decline rule governance*
- Documented incident response process*
- Security contact and escalation path available*
- Breach containment procedures tested*
- Backup and restore readiness for gateway-related configurations or logs*
- Last incident or review date
- Policy review status*
- Remediation owner assigned*
- Compliance readiness*
- Final conclusion*
- Should be Empty: