This is a synthetic cybersecurity portfolio project that demonstrates how PCI DSS security operations evidence can be organized, mapped, tracked, and reported without using any confidential or employer data.
The project focuses on operational evidence readiness for endpoint protection, malware protection, vulnerability management, patch remediation, access reviews, MFA coverage, logging and monitoring, incident response, corrective actions, and management reporting.
This repository contains a representative synthetic sample of a PCI DSS security operations evidence pack. The complete working version, including the extended evidence model, full dashboard workbook, and detailed internal templates, is maintained privately and can be demonstrated during interview discussions.
No employer, client, cardholder, production, or confidential data is used.
This portfolio project is a synthetic operational evidence readiness exercise. It is not a formal PCI DSS assessment, ROC, AOC, SAQ, or QSA-attested report.
Company: GulfPay Card Services
Industry: Payment processing / fintech
Size: 850 employees
Environment: Hybrid infrastructure supporting payment applications
Tools represented: Microsoft Defender, SentinelOne, Intune, SIEM, vulnerability scanner, Zscaler, DLP tool, ticketing system, identity provider
Organizations may already have security tools and operational processes, but PCI DSS evidence is often scattered across endpoint, vulnerability, logging, access control, incident response, and governance teams.
This creates problems such as missing evidence ownership, unclear remediation status, poor vulnerability SLA visibility, access review gaps, malware protection exceptions, logging uncertainty, and weak management reporting.
Build a practical evidence readiness model that shows how security operations evidence can be mapped to PCI DSS references, assigned to owners, tracked for gaps, connected to remediation actions, and summarized through KPI/KRI reporting.
- Representative PCI DSS operational requirement mapping
- Sample evidence register
- Sample endpoint and malware protection rows
- Sample vulnerability remediation rows
- Sample access review and MFA rows
- Sample logging and monitoring rows
- Sample incident response rows
- Sample corrective actions
- Static dashboard image
- Public management summary
- CV and interview talking points
- No working Excel dashboard model
- No complete reusable evidence pack
- No complete PCI mapping
- No confidential data
- No employer or client data
- No production asset names, real tickets, real users, or real vulnerabilities
pci-dss, pci-dss-4, cybersecurity, grc, security-operations, compliance, audit-readiness, vulnerability-management, access-control, logging-monitoring, remediation-tracking, portfolio-project