PCI DSS Requirement 12: Maintain an Information Security PolicyAs outlined in sub-requirements of the other 11 requirements, documenting expectations of the security posture of an organization is fundamental to the success of the organization. Creating a strong information security policy sets the tone, and por...Dec 11, 2023·12 min read
PCI DSS Requirement 8: Identify & Authenticate User Access to System ComponentsDec 7, 2023·8 min read
PCI DSS Requirement 7: Restrict Cardholder Data AccessAssigning permissions carefully is one means of protecting sensitive account data by providing the minimum level of access necessary to perform an employee’s job. Requirement 7 details the means of securing data by keeping those who have access to “n...Dec 6, 2023·4 min read
PCI DSS Requirement 6: Develop and Maintain Secure SystemsPCI DSS Requirement 6 highlights the importance of installing security patches in order to protect systems from being accessed by anyone with malicious intentions. For this to be effective - and to prevent exploitation or compromise of account data -...Dec 5, 2023·7 min read
PCI DSS Requirement 5: Protect All Systems and Networks from Malicious SoftwareMalicious software, also commonly known as malware, is any software or firmware specifically designed to cause damage to, or penetrate the security systems of, a computer system without consent. Malware has the sole intent of compromising the system...Dec 4, 2023·4 min read
PCI DSS Requirement 4: Protect Cardholder Data During Transmission Over Public NetworksVulnerabilities in legacy encryption and authentication protocols for wireless networks are often targeted by malicious individuals aiming to gain access to cardholder data environments (CDE). Merchants using strong encryption gain greater assurance ...Dec 3, 2023·3 min read
PCI DSS Requirement 3: Protect Stored Account DataPublic exposure of stored account and transaction data, either intentional or unintentional, can cause serious damage to a merchant. This is why the PCI SSC has created requirement three of the PCI DSS, which outlines the means and methods of protect...Dec 2, 2023·8 min read
PCI DSS Requirement 2: Securely Configure All System ComponentsAttackers often use default passwords and other vendor default settings to compromise systems. These passwords and settings are both well-known and easily accessible publicly for anyone to find. That is why it is imperative for merchants to update an...Dec 1, 2023·3 min read