PCIP Latest 2023 Already Passed
PCIP Latest 2023 Already Passed Requirement 1 Install and maintain a firewall configuration to protect cardholder data Requirement 2 Do not use vendor supplied defaults for system passwords and other security parameters Requirement 3 Protect stored cardholder data by enacting a formal data retention policy and implement secure deletion methods Requirement 4 Encrypt transmission of cardholder data across open, public networks Requirement 5 Protect all systems against malware and regularly update anti-virus software or programs Requirement 6 Develop and maintain secure systems and applications Requirement 7 Restrict access to cardholder data by business need to know Requirement 8 Identify and authenticate access to system components Requirement 9 Restrict physical access to cardholder data Requirement 10 Track and monitor all access to network resources and cardholder data Requirement 11 Regularly test security systems and processes Requirement 12 Maintain a policy that addresses information security for all personnel Appendix A1 Shared hosting providers must protect the cardholder data environment Appendix A2 Additional PCI DSS Requirements for Entities using SSL/early TLS Appendix A3 Designated Entities Supplemental Validation (DESV) Compensating Controls 1- Meet the intent and rigor of the original PCI requirement 2- Sufficiently offset the risk that the original PCI DSS requirement was designed to defend against 3- Be "above and beyond" other PCI DSS requirements (i.e., not simply in compliance with other requirements) 4- Be commensurate with additional risk imposed by not adhering to original requirement Compensating Controls - To consider Compensating
Información del documento
- Subido en
- 22 de septiembre de 2023
- Número de páginas
- 20
- Escrito en
- 2023/2024
- Tipo
- Examen
- Contiene
- Preguntas y respuestas