2023
Requirement c1 c- cAnswer- cInstall cand cmaintain ca cfirewall cconfiguration cto cprotect
ccardholder cdata
, Requirement c2 c- cAnswer- cDo cnot cuse cvendor csupplied cdefaults cfor csystem
cpasswords cand cother csecurity cparameters
Requirement c3 c- cAnswer- cProtect cstored ccardholder cdata cby cenacting ca cformal
cdata cretention cpolicy cand cimplement csecure cdeletion cmethods
Requirement c4 c- cAnswer- cEncrypt ctransmission cof ccardholder cdata cacross copen,
cpublic cnetworks
Requirement c5 c- cAnswer- cProtect call csystems cagainst cmalware cand cregularly
cupdate canti-virus csoftware cor cprograms
Requirement c6 c- cAnswer- cDevelop cand cmaintain csecure csystems cand capplications
Requirement c7 c- cAnswer- cRestrict caccess cto ccardholder cdata cby cbusiness cneed cto
cknow
Requirement c8 c- cAnswer- cIdentify cand cauthenticate caccess cto csystem ccomponents
Requirement c9 c- cAnswer- cRestrict cphysical caccess cto ccardholder cdata
Requirement c10 c- cAnswer- cTrack cand cmonitor call caccess cto cnetwork cresources
cand ccardholder cdata
Requirement c11 c- cAnswer- cRegularly ctest csecurity csystems cand cprocesses
Requirement c12 c- cAnswer- cMaintain ca cpolicy cthat caddresses cinformation csecurity
cfor call cpersonnel
Appendix cA1 c- cAnswer- cShared chosting cproviders cmust cprotect cthe ccardholder cdata
cenvironment
Appendix cA2 c- cAnswer- cAdditional cPCI cDSS cRequirements cfor cEntities cusing
cSSL/early cTLS
Appendix cA3 c- cAnswer- cDesignated cEntities cSupplemental cValidation c(DESV)
Compensating cControls c- cAnswer- c1- cMeet cthe cintent cand crigor cof cthe coriginal cPCI
crequirement c
2- cSufficiently coffset cthe crisk cthat cthe coriginal cPCI cDSS crequirement cwas cdesigned
cto cdefend cagainst c
3- cBe c"above cand cbeyond" cother cPCI cDSS crequirements c(i.e., cnot csimply cin
ccompliance cwith cother crequirements) c
4- cBe ccommensurate cwith cadditional crisk cimposed cby cnot cadhering cto coriginal
crequirement