1.1
Processes and mechanisms for installing and maintaining network security controls are defined and understood
مجلس معايير أمن بيانات صناعة بطاقات الدفع · 63 ضابطًا رئيسيًا
المعيار مملوك لمجلس معايير أمن بيانات صناعة بطاقات الدفع ونشره محكوم بشروطه، فنعرض هنا هيكله الرسمي: المجموعات الست والمتطلبات الاثني عشر وعناوين البنود الفرعية، مع رابط مباشر لمكتبة المجلس لقراءة النص الكامل. لا نعيد نشر نص المتطلبات.
Processes and mechanisms for installing and maintaining network security controls are defined and understood
Network security controls (NSCs) are configured and maintained
Network access to and from the cardholder data environment is restricted
Network connections between trusted and untrusted networks are controlled
Risks to the CDE from computing devices that connect to both untrusted networks and the CDE are mitigated
Processes and mechanisms for applying secure configurations to all system components are defined and understood
System components are configured and managed securely
Wireless environments are configured and managed securely
Processes and mechanisms for protecting stored account data are defined and understood
Storage of account data is kept to a minimum
Sensitive authentication data is not stored after authorization
Access to displays of full PAN and ability to copy PAN are restricted
Primary account number (PAN) is secured wherever it is stored
Cryptographic keys used to protect stored account data are secured
Where cryptography is used to protect stored account data, key management processes are defined and implemented
Processes and mechanisms for protecting cardholder data with strong cryptography during transmission are defined and documented
PAN is protected with strong cryptography during transmission
Processes and mechanisms for protecting all systems and networks from malicious software are defined and understood
Malicious software is prevented, or detected and addressed
Anti-malware mechanisms and processes are active, maintained, and monitored
Anti-phishing mechanisms protect users against phishing attacks
Processes and mechanisms for developing and maintaining secure systems and software are defined and understood
Bespoke and custom software are developed securely
Security vulnerabilities are identified and addressed
Public-facing web applications are protected against attacks
Changes to all system components are managed securely
Processes and mechanisms for restricting access by business need to know are defined and understood
Access to system components and data is appropriately defined and assigned
Access to system components and data is managed via an access control system(s)
Processes and mechanisms for identifying users and authenticating access are defined and understood
User identification and related accounts for users and administrators are strictly managed
Strong authentication for users and administrators is established and managed
Multi-factor authentication (MFA) is implemented to secure access into the CDE
Multi-factor authentication (MFA) systems are configured to prevent misuse
Use of application and system accounts and associated authentication factors is strictly managed
Processes and mechanisms for restricting physical access to cardholder data are defined and understood
Physical access controls manage entry into facilities and systems containing cardholder data
Physical access for personnel and visitors is authorized and managed
Media with cardholder data is securely stored, accessed, distributed, and destroyed
Point of interaction (POI) devices are protected from tampering and unauthorized substitution
Processes and mechanisms for logging and monitoring all access are defined and documented
Audit logs are implemented to support the detection of anomalies and suspicious activity
Audit logs are protected from destruction and unauthorized modifications
Audit logs are reviewed to identify anomalies or suspicious activity
Audit log history is retained and available for analysis
Time-synchronization mechanisms support consistent time settings across all systems
Failures of critical security control systems are detected, reported, and responded to promptly
Processes and mechanisms for regularly testing security of systems and networks are defined and understood
Wireless access points are identified and monitored, and unauthorized wireless access points are addressed
External and internal vulnerabilities are regularly identified, prioritized, and addressed
External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected
Network intrusions and unexpected file changes are detected and responded to
Unauthorized changes on payment pages are detected and responded to
A comprehensive information security policy that governs and provides direction for protection of the entity's information assets is known and current
Acceptable use policies for end-user technologies are defined and implemented
Risks to the cardholder data environment are formally identified, evaluated, and managed
PCI DSS compliance is managed
PCI DSS scope is documented and validated
Security awareness education is an ongoing activity
Personnel are screened to reduce risks from insider threats
Risk to information assets associated with third-party service provider (TPSP) relationships is managed
Third-party service providers (TPSPs) support their customers' PCI DSS compliance
Suspected and confirmed security incidents that could impact the CDE are responded to immediately
أُعدت هذه الصفحة من النص الرسمي حرفيًا عبر إحكام من سايبرز.بز · افتح المكتبة التفاعلية