Internal Security Assessor (ISA)

PCIComplianceHubLast updated

An employee who has completed PCI Security Standards Council training and certification, qualifying them to perform PCI DSS assessments for their own organization. An ISA can complete internal assessments and Self-Assessment Questionnaires, and some payment brands accept ISA involvement where a Qualified Security Assessor would otherwise be required. An ISA cannot assess other organizations; that requires a QSA.