Standards & Compliance

PCI DSS

Payment Card Industry Data Security Standard

PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for organizations that process, store, or transmit payment card data. Developed by PCI Security Standards Council (Visa, Mastercard, Amex, Discover, JCB).

12 PCI DSS Requirements

Build and Maintain a Secure Network

  1. Install and maintain a firewall
  2. Do not use vendor-supplied defaults

Protect Cardholder Data

  1. Protect stored cardholder data
  2. Encrypt transmission of cardholder data

Maintain a Vulnerability Management Program

  1. Use and update anti-virus software
  2. Develop secure systems

Implement Strong Access Control

  1. Restrict access to data
  2. Identify and authenticate users
  3. Restrict physical access

Monitoring and Testing

  1. Track and monitor all access
  2. Regularly test security systems

Security Policies

  1. Maintain information security policy

Related Terms

External Links

Category

ISO 27001, PCI DSS, GDPR, SOC 2, regulatory requirements