a.k.a Payment Card Security Made Stupid Simple
Video: The 12 Steps to PCI Compliance
- Build and Maintain a Secure Network
- Firewall
- Use secure passwords
- Protect Cardholder data
- Encryption
- Maintain a vulnerability management program
- Anti-virus
- Secure systems and healthy applications
- System updates
- Implement strong access control methods
- SSO / AD
- Need to know basis
- Each user must have a unique id.
- Physical access to the data must be restricted
- Regularly monitor and test networks
- All access must be tracked
- Log monitoring
- Test Security and processes
- Maintain an Information (Data) Security Policy