What is PCI DSS?
PCI DSS is an information security standard for storing, transferring, and processing credit card information, created by MasterCard, American Express, Visa, JCB International, and Discover Financial Services.
Any organization storing or processing credit card information should comply with PCI DSS. The PCI has the following requirements:
- Use a firewall to protect the PCI environment
- Set password policies
- Protect stored credit card data
- Encrypt credit card data at transit
- Use anti-virus software
- Conduct patch management
- Restrict access to credit card data
- Assign a unique identity to each person with access to credit card data
- Restrict physical access to credit card data
- Conduct log management
- Conduct vulnerability assessments and penetration tests
- Conduct risk assessments and document the process
Any provider or organization that stores, transfers, or processes credit card information should follow the...