Tabletop exercise

PCI DSS v4.0 tabletop exercise

Protecting cardholder data: encryption, access control, monitoring.

We can run the PCI DSS v4.0 exercise for your team, or set you up as a facilitator to run it yourself.

What the room works through

PCI DSS v4.0 requirements

Cardholder data environment. Use requirement refs such as 1.2.1, 3.5.1, 8.3.6, 10.2.1 and domains matching the twelve requirement groups.

Clauses
36
Rounds
10 across two stages
Room size
Up to 20 participants

Stage 1 — assess

Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a PCI DSS v4.0 clause.

Stage 2 — survive

Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.

What you take away

  • Clause-by-clause coverage across PCI DSS v4.0
  • A gap list ranked by what the room could not defend
  • Per-table divergence, so you can see where opinion split
  • Word and CSV exports plus a drafted findings narrative

New to facilitating? Start with the facilitator manual or read the session walkthrough.

Other standards