• PCI DSS User Access Review Checklist

    Complete this checklist to ensure user access aligns with PCI DSS requirements. Review all relevant user accounts and access controls as part of your periodic compliance process.
  • Date of Review*
     - -
    2 digit month, 2 digit day, 4 digit year
  • Are all user accounts current, active, and authorized?*
  • Have all dormant, inactive, or terminated user accounts been disabled or removed?*
  • Does each user have only the minimum necessary access (least privilege)?*
  • Are all privileged or administrative accounts reviewed and justified?*
  • Has access been reviewed for all third-party or vendor accounts?*
  • Are access approval and change records documented for all users?*
  • Is periodic user access review performed as per PCI DSS policy?*
  • Have all exceptions or issues identified during this review been remediated?*
  • Should be Empty:
Select theme: