PCI DSS assessment under 4.0 can include both defined and customized approaches but, it must be designed in consensus with the Qualified Security Assessor (QSA). Before considering the customized approach as an option, organizations must ensure that they have robust security processes and risk management practices in place.

APAC
