# SP-026 PCI Full Environment

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for a fully PCI DSS compliant cardholder data environment. Covers CDE scoping and segmentation, cardholder data protection with encryption and key management, access control for payment systems, audit logging and monitoring, vulnerability management, and physical security for payment processing infrastructure.
Use when: Apply this pattern where you are a merchant or payment services processor that stores, transmits, or processes payment card data in your own infrastructure. This includes organisations operating their own payment terminals, e-commerce platforms processing card-not-present transactions, payment processors and acquirers, and any service provider that can affect the security of cardholder data on behalf of other...
Not when: Do not use this pattern where you plan to reduce compliance scope using tokenisation or remove the environment from scope entirely by using a third-party payment services gateway.

## Controls (32, NIST SP 800-53 ids)
- Critical (10): AC-02, AC-06, AU-02, AU-06, CM-02, RA-05, SC-07, SC-09, SC-12, SC-13
- Important (14): AU-08, AU-09, CA-02, CA-07, CM-03, CM-08, IR-01, MP-06, PE-03, RA-03, SI-02, SI-03, SI-04, SI-07
- Standard (8): AC-18, AC-19, MP-03, PE-07, PS-03, SI-05, SI-06, SI-09
- Withdrawn from SP 800-53 by NIST: PE-07 (now in PE-02, PE-03); SC-09 (now in SC-08); SI-09 (now in AC-02, AC-03, AC-05, AC-06)

## What each critical control mitigates (10)
- AC-02 Account Management: T-PC-005
- AC-06 Least Privilege: T-PC-001, T-PC-005, T-PC-006
- AU-02 Event Logging: T-PC-006, T-PC-009
- AU-06 Audit Record Review, Analysis, and Reporting: T-PC-006, T-PC-009
- CM-02 Baseline Configuration: T-PC-003, T-PC-004, T-PC-005
- RA-05 Vulnerability Monitoring and Scanning: T-PC-007
- SC-07 Boundary Protection: T-PC-002, T-PC-004, T-PC-008
- SC-09 Transmission Confidentiality: T-PC-002
- SC-12 Cryptographic Key Establishment and Management: T-PC-001
- SC-13 Cryptographic Protection: T-PC-001, T-PC-002

## Threats and the controls that mitigate them (10)
- T-PC-001 Cardholder Data Theft at Rest (Database Compromise, Backup Theft): SC-13, SC-12, AC-06, MP-06
- T-PC-002 Cardholder Data Interception in Transit (Network Sniffing, MITM): SC-09, SC-13, SC-07, SI-04
- T-PC-003 Web Application Attacks (SQL Injection, XSS, Magecart-style Skimming): SI-07, SI-06, SI-09, CM-02
- T-PC-004 POS Malware and Memory Scraping: SI-03, CM-02, SC-07, SI-07
- T-PC-005 Exploitation of Default Credentials and Misconfigurations: CM-02, CM-03, AC-02, AC-06
- T-PC-006 Insider Threat (Privileged User Data Exfiltration): AC-06, AU-02, AU-06, PS-03
- T-PC-007 Unpatched Vulnerabilities in CDE Systems: RA-05, SI-02, SI-05, CM-08
- T-PC-008 Inadequate Network Segmentation (Scope Expansion): SC-07, CA-07, CM-08, RA-03
- T-PC-009 Audit Log Tampering or Gaps: AU-09, AU-08, AU-06, AU-02
- T-PC-010 Physical Unauthorised Access to CDE Infrastructure: PE-03, PE-07, MP-03, MP-06

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-026/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-026/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 27 KB: /api/v1/patterns/SP-026
- Page for people: /patterns/sp-026/
- Related: SP-013 Data Security Pattern; SP-018 Information Security Management System; SP-025 Advanced Monitoring and Detection; SP-010 Identity Management Pattern; SP-017 Secure Network Zone Module

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
