PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

Targeted risk analysis — TRA

A targeted risk analysis (TRA) is the documented analysis PCI DSS v4.x requires when an entity chooses the frequency of a periodic activity, or uses the customised approach.

What it means in practice

Requirement 12.3.1 sets out what a TRA must contain, including the asset being protected, the threat, the factors contributing to likelihood and impact, and the review frequency.
TRAs are reviewed at least once every 12 months and after significant change.
Common TRA subjects are anti-malware scan frequency, POI device inspection frequency and periodic log review of lower-risk systems.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.