Payment Card Industry Data Security Standard (PCI DSS)

PCI - Security Standards Council - Participating Organisation

Why do we need it?

Protecting your customers, securing the industry

The card payment industry is facing the increasing threat of data theft. To date, criminals have stolen millions of customer card records. In 2008, VISA reported that merchants could have avoided most security breaches if they had implemented the following measures:

  • Remove sensitive authentication data and limit data retention.
  • Protect the perimeter, internal and wireless networks.
  • Secure application.
  • Protect through monitoring and access control.

Setting the standard for security

The industry needed to act. So, to secure customer data and confidence, card payment companies joined forces to create the Payment Card Industry Data Security Standard (PCI DSS). The standard features 12 requirements that aim to safeguard sensitive card data across the card payment industry.

Category # Description
Build and maintain a secure network 1 Install and maintain a firewall configuration to protect cardholder data
2 Don't use vendor-supplied defaults for system passwords and other security parameters.
Protect cardholder data 3 Protect stored cardholder data.
4 Encrypt transmission of cardholder data across open, public networks.
Maintain a vulnerability management program 5 Use and regularly update anti-virus software.
6 Develop and maintain secure systems and applications.
Implement strong access control measures 7 Track and monitor all access to network resources and cardholder data.
8 Assign a unique ID to each person with computer access.
9 Restrict physical access to cardholder data.
Regularly monitor and test networks 10 Track and monitor all access to network resources and cardholder data.
11 Regularly test security systems and processes.
Maintain an information security policy 12 Maintain a policy that addresses information security.

back