PCI DSS - Compliance Project

PCI DSS - Compliance Project
PCI Compliance

It's a project I was part of to ensure that the company network and systems meet the PCI DSS Compliance for Data Protection and security and also for customer peace of mind.

But what is PCI DSS? What does it mean to be PCI DSS Compliant?

By definition, the Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle branded credit cards from major card schemes.

A PCI DSS Compliance is a set of requirements for any business that stores, processes, or transmits payment cardholder data, to ensure that any transaction or payment made through the store is secured and safe.

Processing Card Payments, VISA, MasterCard, American Express

PCI DSS requirements v3

  1. Install and maintain a firewall configuration to
    protect cardholder data
  2. Do not use vendor-supplied defaults for system passwords and other security parameters
  3. Protect stored cardholder data
  4. Encrypt transmission of cardholder data across open, public networks
  5. Use and regularly update anti-virus software or programs
  6. Develop and maintain secure systems and applications
  7. Restrict access to cardholder data by business need to know
  8. Assign a unique ID to each person with computer access
  9. Restrict physical access to cardholder data
  10. Track and monitor all access to network resources and cardholder data
  11. Regularly test security systems and processes
  12. Maintain a policy that addresses information security for all personnel

Sources:
pcisecuritystandards.org
PCI DSS requirements v3
microsoft.com