home icon pages icon
  • Build and Maintain a Secure Network and Systems

    Requirement 1Install and maintain a firewall configuration to protect cardholder data

    Requirement 2Do not use vendor-supplied defaults for system passwords and other security parameters

  • Protect Cardholder Data

    Requirement 3Protect stored cardholder data

    Requirement 4Encrypt transmission of cardholder data across open, public networks

  • Maintain a Vulnerability Management Program

    Requirement 5Protect all systems against malware and regularly update anti-virus software or programs

    Requirement 6Develop and maintain secure systems and applications

  • Implement Strong Access Control Measures

    Requirement 7Restrict access to cardholder data by business need to know

    Requirement 8Identify and authenticate access to system components

    Requirement 9Restrict physical access to cardholder data

  • Regularly Monitor and Test Networks

    Requirement 10Track and monitor all access to network resources and cardholder data

    Requirement 11Regularly test security systems and processes

  • Maintain an Information Security Policy

    Requirement 12Maintain a policy that addresses information security for all personnel

  • Appendix AAdditional PCI DSS Requirements for Shared Hosting Providers

    Appendix BCompensating Controls

    Appendix CCompensating Controls Worksheet

    Appendix DSegmentation and Sampling of Business Facilities/System Components

PCI DSS Resources

Requirements and Security Assessment Procedures


Resources Quick Links

  • PCI DSS organization site resources
  • PCI DSS Applicability Information
  • Relationship between PCI DSS and PA-DSS
  • Scope of PCI DSS Requirements
  • Best Practices for Implementing PCI DSS into Business-as-Usual Processes
  • For Assessors: Sampling of Business Facilities/System Components
  • Compensating Controls
  • Instructions and Content for Report on Compliance
  • PCI DSS Assessment Process
  • Detailed PCI DSS Requirements and Security Assessment Procedures