Controls Matrix

PCIComplianceHubLast updated

The document an organization produces for each requirement it meets through the Customized Approach, describing the control in place, how it meets the customized approach objective, how its effectiveness is tested and maintained, and who is accountable for it. Together with the targeted risk analysis, the controls matrix is what an assessor uses to derive bespoke testing procedures for that control. PCI DSS Appendix E provides a sample template.