|
[PCI DSS 3.0] 8.7 All access to any database containing cardholder data (including access by applications, adminis
|
|
0
|
5285
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.6 Where other authentication mechanisms are used
|
|
0
|
2564
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.5.1 Additional requirement for service providers: Service providers with remote access to customer
|
|
0
|
2259
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.5 Do not use group, shared, or generic IDs, passwords, or other authentication methods as follows:
|
|
0
|
3003
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.4 Document and communicate authentication procedures and policies to all users including:
|
|
0
|
2384
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.3 Incorporate two-factor authentication for remote network access originating from outside the net
|
|
0
|
1815
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.6 Set passwords/phrases for first- time use and upon reset to a unique value for each user, and
|
|
0
|
2436
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.5 Do not allow an individual to submit a new password/phrase that is the same as any of the last
|
|
0
|
2823
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.4 Change user passwords/passphrases at least every 90 days.
|
|
0
|
2804
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.3 Passwords/phrases must meet the following:
|
|
0
|
2583
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.2 Verify user identity before modifying any authentication credential—for example, performing pa
|
|
0
|
2546
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2.1 Using strong cryptography, render all authentication credentials (such as passwords/phrases) u
|
|
0
|
4132
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.2 In addition to assigning a unique ID, ensure proper user-authentication management for non-consu
|
|
0
|
1668
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.8 If a session has been idle for more than 15 minutes, require the user to re-authenticate to re
|
|
0
|
3662
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.7 Set the lockout duration to a minimum of 30 minutes or until an administrator enables the user
|
|
0
|
2588
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.6 Limit repeated access attempts by locking out the user ID after not more than six attempts.
|
|
0
|
3321
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.5 Manage IDs used by vendors to access, support, or maintain system components via remote access
|
|
0
|
2856
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.4 Remove/disable inactive user accounts at least every 90 days.
|
|
0
|
4248
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.3 Immediately revoke access for any terminated users.
|
|
0
|
2897
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.2 Control addition, deletion, and modification of user IDs, credentials, and other identifier ob
|
|
0
|
5331
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1.1 Assign all users a unique ID before allowing them to access system components or cardholder da
|
|
0
|
2448
|
September 23, 2014
|
|
[PCI DSS 3.0] 8.1 Define and implement policies and procedures to ensure proper user identification management for
|
|
0
|
1673
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.3 Ensure that security policies and operational procedures for restricting access to cardholder da
|
|
0
|
12606
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.2.3 Default “deny-all” setting.
|
|
0
|
13745
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.2.2 Assignment of privileges to individuals based on job classification and function.
|
|
0
|
12093
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.2.1 Coverage of all system components
|
|
0
|
12972
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.2 Establish an access control system for systems components that restricts access based on a user’
|
|
0
|
11965
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.1.4 Require documented approval by authorized parties specifying required privileges.
|
|
0
|
13027
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.1.3 Assign access based on individual personnel’s job classification and function.
|
|
0
|
12523
|
September 23, 2014
|
|
[PCI DSS 3.0] 7.1.2 Restrict access to privileged user IDs to least privileges necessary to perform job responsibi
|
|
0
|
12606
|
September 23, 2014
|