Tabletop exercise
PCI DSS v4.0 tabletop exercise
Protecting cardholder data: encryption, access control, monitoring.
We can run the PCI DSS v4.0 exercise for your team, or set you up as a facilitator to run it yourself.
What the room works through
PCI DSS v4.0 requirements
Cardholder data environment. Use requirement refs such as 1.2.1, 3.5.1, 8.3.6, 10.2.1 and domains matching the twelve requirement groups.
- Clauses
- 36
- Rounds
- 10 across two stages
- Room size
- Up to 20 participants
Stage 1 — assess
Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a PCI DSS v4.0 clause.
Stage 2 — survive
Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.
What you take away
- Clause-by-clause coverage across PCI DSS v4.0
- A gap list ranked by what the room could not defend
- Per-table divergence, so you can see where opinion split
- Word and CSV exports plus a drafted findings narrative
New to facilitating? Start with the facilitator manual or read the session walkthrough.