معيار أمن بيانات بطاقات الدفع (PCI DSS v4.0.1)

مجلس معايير أمن بيانات صناعة بطاقات الدفع · 63 ضابطًا رئيسيًا

النسخة التفاعلية والتقييم ←

المعيار مملوك لمجلس معايير أمن بيانات صناعة بطاقات الدفع ونشره محكوم بشروطه، فنعرض هنا هيكله الرسمي: المجموعات الست والمتطلبات الاثني عشر وعناوين البنود الفرعية، مع رابط مباشر لمكتبة المجلس لقراءة النص الكامل. لا نعيد نشر نص المتطلبات.

A. بناء شبكة وأنظمة آمنة وصيانتها

1 المتطلب 1: تركيب ضوابط أمن الشبكات والحفاظ عليها

1.1

Processes and mechanisms for installing and maintaining network security controls are defined and understood

1.2

Network security controls (NSCs) are configured and maintained

1.3

Network access to and from the cardholder data environment is restricted

1.4

Network connections between trusted and untrusted networks are controlled

1.5

Risks to the CDE from computing devices that connect to both untrusted networks and the CDE are mitigated

2 المتطلب 2: تطبيق إعدادات آمنة على جميع مكوّنات الأنظمة

2.1

Processes and mechanisms for applying secure configurations to all system components are defined and understood

2.2

System components are configured and managed securely

2.3

Wireless environments are configured and managed securely

B. حماية بيانات الحساب

3 المتطلب 3: حماية بيانات الحساب المخزَّنة

3.1

Processes and mechanisms for protecting stored account data are defined and understood

3.2

Storage of account data is kept to a minimum

3.3

Sensitive authentication data is not stored after authorization

3.4

Access to displays of full PAN and ability to copy PAN are restricted

3.5

Primary account number (PAN) is secured wherever it is stored

3.6

Cryptographic keys used to protect stored account data are secured

3.7

Where cryptography is used to protect stored account data, key management processes are defined and implemented

4 المتطلب 4: حماية بيانات حاملي البطاقات بالتشفير أثناء النقل

4.1

Processes and mechanisms for protecting cardholder data with strong cryptography during transmission are defined and documented

4.2

PAN is protected with strong cryptography during transmission

C. برنامج إدارة الثغرات

5 المتطلب 5: حماية الأنظمة والشبكات من البرمجيات الضارة

5.1

Processes and mechanisms for protecting all systems and networks from malicious software are defined and understood

5.2

Malicious software is prevented, or detected and addressed

5.3

Anti-malware mechanisms and processes are active, maintained, and monitored

5.4

Anti-phishing mechanisms protect users against phishing attacks

6 المتطلب 6: تطوير أنظمة وبرمجيات آمنة وصيانتها

6.1

Processes and mechanisms for developing and maintaining secure systems and software are defined and understood

6.2

Bespoke and custom software are developed securely

6.3

Security vulnerabilities are identified and addressed

6.4

Public-facing web applications are protected against attacks

6.5

Changes to all system components are managed securely

D. ضوابط قوية للتحكم بالوصول

7 المتطلب 7: تقييد الوصول وفق الحاجة إلى المعرفة

7.1

Processes and mechanisms for restricting access by business need to know are defined and understood

7.2

Access to system components and data is appropriately defined and assigned

7.3

Access to system components and data is managed via an access control system(s)

8 المتطلب 8: تحديد هوية المستخدمين والتحقق من الوصول

8.1

Processes and mechanisms for identifying users and authenticating access are defined and understood

8.2

User identification and related accounts for users and administrators are strictly managed

8.3

Strong authentication for users and administrators is established and managed

8.4

Multi-factor authentication (MFA) is implemented to secure access into the CDE

8.5

Multi-factor authentication (MFA) systems are configured to prevent misuse

8.6

Use of application and system accounts and associated authentication factors is strictly managed

9 المتطلب 9: تقييد الوصول المادي لبيانات حاملي البطاقات

9.1

Processes and mechanisms for restricting physical access to cardholder data are defined and understood

9.2

Physical access controls manage entry into facilities and systems containing cardholder data

9.3

Physical access for personnel and visitors is authorized and managed

9.4

Media with cardholder data is securely stored, accessed, distributed, and destroyed

9.5

Point of interaction (POI) devices are protected from tampering and unauthorized substitution

E. المراقبة والاختبار الدوري للشبكات

10 المتطلب 10: تسجيل ومراقبة كل وصول للأنظمة وبيانات البطاقات

10.1

Processes and mechanisms for logging and monitoring all access are defined and documented

10.2

Audit logs are implemented to support the detection of anomalies and suspicious activity

10.3

Audit logs are protected from destruction and unauthorized modifications

10.4

Audit logs are reviewed to identify anomalies or suspicious activity

10.5

Audit log history is retained and available for analysis

10.6

Time-synchronization mechanisms support consistent time settings across all systems

10.7

Failures of critical security control systems are detected, reported, and responded to promptly

11 المتطلب 11: اختبار أمن الأنظمة والشبكات دوريًا

11.1

Processes and mechanisms for regularly testing security of systems and networks are defined and understood

11.2

Wireless access points are identified and monitored, and unauthorized wireless access points are addressed

11.3

External and internal vulnerabilities are regularly identified, prioritized, and addressed

11.4

External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected

11.5

Network intrusions and unexpected file changes are detected and responded to

11.6

Unauthorized changes on payment pages are detected and responded to

F. سياسة أمن المعلومات

12 المتطلب 12: دعم أمن المعلومات بالسياسات والبرامج المؤسسية

12.1

A comprehensive information security policy that governs and provides direction for protection of the entity's information assets is known and current

12.2

Acceptable use policies for end-user technologies are defined and implemented

12.3

Risks to the cardholder data environment are formally identified, evaluated, and managed

12.4

PCI DSS compliance is managed

12.5

PCI DSS scope is documented and validated

12.6

Security awareness education is an ongoing activity

12.7

Personnel are screened to reduce risks from insider threats

12.8

Risk to information assets associated with third-party service provider (TPSP) relationships is managed

12.9

Third-party service providers (TPSPs) support their customers' PCI DSS compliance

12.10

Suspected and confirmed security incidents that could impact the CDE are responded to immediately

أُعدت هذه الصفحة من النص الرسمي حرفيًا عبر إحكام من سايبرز.بز · افتح المكتبة التفاعلية