NOTE:

On 19 March 2024, the PCI SSC took the decision to discontinue the use of Items Noted for Improvement (INFI) forms, introduced with version 4.0 of the PCI DSS standard. This decision has been made with the support of the PCI Global Executive Assessor Roundtable and the PCI Board of Advisors, who considered that the use of this form introduced additional problems in the management of PCI DSS compliance in organizations.

As of that date, QSA advisors are not required to fill out this form, having to use their "good judgment" (good judgement) to determine whether or not a requirement is met in the event that a problem was identified during the compliance assessment.

More information here: https://blog.pcisecuritystandards.org/items-noted-for-improvement-infi-worksheet-discontinued

The information described below is kept as a historical reference only.


One of the most important concepts introduced in PCI DSS v4.0 was to promote security as an ongoing process.  Therefore, the PCI SSC has developed a new worksheet called Items Noted for Improvement (INFI), where the QSA or ISA advisor can report any activity that could be improved in the entity if during the compliance assessment a problem was detected that had to be corrected to align with the standard.

Brief history of INFI

During the development of PCI DSS v4.0 multiple comments and suggestions were received from different entities (Request For Comments – RFCs) which, in one way or another, were analysed and added as improvements to this new version of the standard. Unlike PCI DSS v3.2.1, version 4.0 of the standard was intended to provide a tool to follow up on any control that had presented problems during the compliance assessment process.

Therefore, in the initial PCI DSS v4.0 compliance reporting templates (Report on Compliance – RoC , Attestation of Compliance – AoC and Self-Assessment Questionnaires – SAQ) added a new compliance status for each check that complemented the already traditional ones In Place, Not in Place, Not Applicable y Not Tested: In Place with Remediation. The goal of this option was to promote security as an ongoing process, providing organizations with a means to identify areas that need improvement year after year.

‘In Place with Remediation’ – Currently not used in PCI DSS reports

This new status was present once the standard and its associated documents were published in March 2022. However, before long, this change began to be the target of different criticism from merchants and service providers. Taking into account that compliance reports (especially the AoC) are usually shared with third parties (payment brands, acquirers, customers, etc.), it was not good to expose "publicly" their problems of alignment with the standard, give a false image of "different qualities of compliance" between companies and even give rise to misunderstandings, especially with insurance companies. Apart from this, it was not clear how or who would be responsible for monitoring the controls listed as In Place with Remediation after completion of the assessment.

For that reason, on 14 December 2022 the PCI SSC chose to remove that compliance status from the reports, but did not clarify what his replacement would be. With the removal from this state it went back to the starting point: There was no tool to report improvements to the entity once the compliance assessment had been completed …

Introduction to Items Noted for Improvement (INFI)

Almost six months later and after many internal reviews, the 28 June 2023 PCI SSC announced that the replacement of In Place with Remediation I was ready: PCI DSS v4.x Items Noted for Improvement (INFI). Generally speaking, the objective of INFI is practically the same as the state of In Place with Remediation but documented on an independent, internal form: List those requirements that were detected as non-compliances but that were remedied by the entity evaluated within a framework of continuous improvement. For this to be valid, the advisor must be sure that the reason why the request failed has been identified, that an effective correction has been implemented and that additional measures have been put in place to prevent the same failure from occurring again.

Some of the features of the INFI worksheet (Items Noted for Improvement (INFI) Worksheet) are:

      • The use of the INFI worksheet is mandatory for assessments performed with PCI DSS version 4.x and optional in assessments under PCI DSS v3.2.1.
      • It is a worksheet intended for use internal between the assessor and the assessed entity. By default, this document is not provided to any other entity, including acquiring entities, payment brands, etc.
      • The results of the INFI worksheet are not included in any compliance document (RoC or AoC).
      • The INFI worksheet must be filled out regardless of whether or not remediated requirements were identified. For compliance assessments that use a Self-Assessment Questionnaire (SAQ), the use of INFI is only a recommendation.
      • This document must be signed by the QSA advisor. In the case of assessments carried out by a Internal Security Assessor (ISA), your signature is recommended but not mandatory.
      • Elements of non-compliance subject to INFI remediation can be detected both by the advisor and proactively by the assessed entity itself.

On the other hand, it is important to know what activities NO can be managed with INFI:

  • Non-compliances with the requirements once the evaluation has been completed: If the advisor identifies a non-compliance and the non-compliance is not remedied BEFORE the evaluation is completed, this result will be reported in the corresponding RoC/SAQ and AoC.
  • Management of requirements using controls alternative to those described in the standard (Defined Approach/Defined Approach): In this case, compensatory controls and/or a personalised approach should be used (Customized Approach) together with their respective forms.

Use of INFI

The process for determining whether a requirement should be categorized asNot in Place» or managed using the INFI worksheet is as follows:

Flow of actions to determine the use of INFI

In this regard:

  • If it is found that the requirement complies with the provisions of the standard (either with direct compliance, through compensatory controls or using the personalized approach (customized approach)), is reported as "In Place".
  • If it is found that the requirement did not meet the objective of the standard BUT the entity implemented corrective controls to remedy it and prevent the problem from not occurring again BEFORE the evaluation is completed, it is reported as "In Place" in the RoC/AoC/SAQ and its management process is described in an INFI worksheet.
  • If it is found that the requirement is not met, it is reported as "Not in Place".

To guide the development of this activity, three main documents are available:

The worksheet has the following fields that must be filled in by the advisor:

Reporting requirements under INFI

Finally, the advisor must complete the "Recognition and attestation" section (Acknowledgement and Attestation) indicating whether requirements were identified under INFI or not:

Recognition and attestation of INFI

Finally:

  • The form is signed by the advisor (mandatory for QSA and recommended for ISA)
  • The acceptance of the INFI by the entity is signed. This action is optional, as it is not essential for the entity to accept the document.

What should be done once an INFI worksheet is received?

Once the formal compliance assessment is completed, the advisor must deliver the INFI worksheet to the assessed entity. Depending on its internal processes, the entity may delegate these recommendations to the area of Compliance, Risks or even to a third party to carry out the necessary follow-up.

In the same way, this document will provide valuable information to the advisor in future evaluations, since it will allow him to know and understand what the entity failed in the past and how it managed its non-compliances. If the advisor confirms that this non-compliance is still recurrent and that the improvement actions do not allow the proper management of your risk, you can report the request with problems such as "Not in Place".

Some examples of INFI application

Any of the requirements of PCI DSS, if it detects non-compliance during its evaluation, may be susceptible to being managed through INFI. This includes requirements with periodic implementation or single execution requirements that were not implemented correctly and temporarily exposed the institution to risk. Some examples are cited in the INFI guidance documents listed above:

  • The entity did not install a critical security update within 30 days of its report, but this incident was identified and corrected in the following quarter through vulnerability scanning.
  • An insecure configuration in a network asset was identified by the advisor but was corrected by the entity BEFORE finalizing the assessment.
  • An entity’s regulatory framework document was not aligned with the requirements of the standard but was updated by the entity BEFORE the assessment was finalised.
  • An asset was not contemplated within the scope of PCI DSS and therefore was not configured properly. However, the entity identified and correctly configured it a month after putting it into production.
  • A subset of the staff had not completed training in PCI DSS within the 12 months stipulated by the standard. This was corrected BEFORE the evaluation was completed.

As can be concluded, the INFI worksheet is a very interesting tool to maintain control of internal errors in PCI DSS compliance and its actions to remedy the associated risk, which demonstrates the maturity and evolution of the PCI DSS standard towards a continuous improvement approach.

Posted by David Acosta

Qualified Security Assessor (QSA) for PCI DSS, PCI PIN, PCI 3DS, P2PE and PCI TSP. CISSP, CISA, CISM, CRISC, C|EH, C|HFI.

Leave to Reply