Targeted Risk Analysis (TRA)

PCIComplianceHubLast updated

A documented risk analysis that PCI DSS v4.x requires in two situations. Under Requirement 12.3.1, an organisation performs one for each requirement that lets it set its own frequency for an activity, justifying the interval it chooses. Under Requirement 12.3.2, it performs one for each requirement met through the Customized Approach. Every targeted risk analysis is reviewed at least once every 12 months, and the Council publishes sample templates, referenced from Appendix E of the standard. It is narrow by design, addressing a single requirement rather than serving as a general enterprise risk assessment.

Applies to. Any entity using a frequency the standard leaves to it, such as the 11.6.1 evaluation interval or the frequency of POI device inspections, and any entity using the customised approach for a requirement.
Example. An entity wants to evaluate its payment pages every fortnight rather than weekly under 11.6.1. Its analysis for that requirement identifies the assets protected, the threat, the factors affecting likelihood and impact, and justifies the interval; it is reviewed within 12 months. Without that document, weekly applies.
Limits. 12.3.1 lists what the analysis must contain: the assets being protected, the threat the requirement guards against, the factors that contribute to likelihood and impact, a justified frequency, and a review at least every 12 months with an update where needed. An analysis that concludes 'annually is fine' without those elements is not one. It is per requirement and does not replace the entity's wider risk assessment.
In PCI DSS v4.0.1. 12.3.1, 12.3.2