Guidance for Understanding PCI Security Requirements

Searching for information on how to make sure you keep card data secure?

Guidance for Requirements 1 and 2: Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

Guidance for Requirements 3 and 4: Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks

Guidance for Requirements 5 and 6: Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software or programs
Requirement 6: Develop and maintain secure systems and applications

Guidance for Requirements 7, 8, and 9: Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need to know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data

Guidance for Requirements 10 and 11: Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes

Guidance for Requirement 12: Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security for employees and contractors

Source: https://www.pcisecuritystandards.org/pdfs/pci_dss_saq_navigating_dss.pdf

CONTACT US
Close