PCI Certification requires you have all of your **information security policies** documented. This is a large effort but is the only way to be sure you are following the best practices required to secure your sensitive information. ==Templates== The minimum contents of the Information Security Policy are dictated in the SAQ questionaire. Depending on the type of business you do and the SAQ form you file with, your requirements will vary. Many sources of templates exist. Some of them are: * [[https://www.trustkeeper.net/SPA/SecurityPolicyAdvisor.html]]. This web site is available for users of TrustKeeper for their PCI certification. Though this might be a good start and has several other policy templates, unfortunately a policy guide is //not// provided for SAQ-D compliance (only A-C). * [[http://www.pcipolicy.com]]. This web site sells PCI compliance templates. After just a few questions (and $59) they will produce to a simple merged Word or PDF document. It may be frustrating to pay so much for a simple merged document that you will still have to review, edit, and attest to; but it is way better than starting from scratch.