1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
The Payment Card Industry Data Security Standard establishes technical and operational requirements for merchants, processors, acquirers, issuers and service providers on the secure acceptance, storage, processing, and transmission of cardholder data in order to avoid fraud and data breaches.
BitSpartan helps organizations fulfill their PCI DSS initiatives by conducting gap assessments, providing SAQ services, and a suite of security services to meet the technical and operational requirements of the standard.
The Payment Card Industry Data Security Standard establishes technical and operational requirements for merchants, processors, acquirers, issuers, and service providers on the secure acceptance, storage, processing, and transmission of cardholder data in order to avoid fraud and data breaches. There are six main goals and twelve specific requirements tied to these goals.
1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder
Data
3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across open, public networks
5. Protect all systems against malware and regularly update antivirus software or programs
6. Develop and maintain secure systems and applications
7. Restrict access to cardholder data by business need to know
8. Identify and authenticate access to system components
9. Restrict physical access to cardholder data
Regularly Monitor and Test
Networks
10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
12. Maintain a policy that addresses information security for all personnel