You must have a written security policy. It must be communicated to new employees,
and have management sponsorship, as well as designating contact information for
hosts and emergencies.
Annual assessment are required.
Quarterly vulnerability scans (annual for level 4 merchants), are required (internal
and external).