PCI DSS Compliance: A Brief Overview
PCI DSS compliance requires organizations that process credit or debit card payments to meet 12 specific security requirements—including firewall installation, password management, data encryption, access restrictions, and regular security testing—established by major card brands and overseen by the PCI Security Standards Council to protect cardholder data from fraud and breaches.
Compliance with the Payment Card Industry Data Security Standard (PCI DSS) means meeting 12 specific compliance requirements. If your organization processes credit- or debit card payments, you must comply with them.
What are the 12 PCI DSS compliance requirements?
- 1.Install and maintain a firewall to protect cardholder data.
- 2.Do not use vendor-supplied defaults for system passwords and other security parameters.
- 3.Protect stored cardholder data.
- 4.Encrypt transmission of cardholder data across open, public networks.
- 5.Use and regularly update antivirus software.
- 6.Develop and maintain secure systems and applications.
- 7.Restrict access to cardholder data by business need-to-know.
- 8.Assign a unique ID to each person with computer access to prevent unauthorized access.
- 9.Restrict physical access to cardholder data.
- 10.Track and monitor all access to network resources and cardholder data.
- 11.Regularly test security systems and processes.
- 12.Maintain a policy that addresses information security.
Below, we’ll explore these requirements and how to comply with each. But first, let’s determine whether your entity needs to comply with PCI DSS and to what extent.
What is PCI DSS?
Visa, MasterCard, Discover Financial Services, JCB International, and American Express developed the Payment Card Industry Data Security Standard (PCI DSS) in 2004. The Payment Card Industry Security Standards Council (PCI SSC) oversees the compliance program, which protects credit and debit card transactions from fraud and data theft.
It is a requirement for every company that conducts credit or debit card transactions. PCI certification helps companies protect sensitive data and establish reliable partnerships with clients.
PCI DSS: Who Needs to Comply?
The Payment Card Industry Data Security Standard (PCI DSS) is an information security framework intended to help merchants and service providers protect credit and debit card transactions from data breaches.
PCI DSS is not a law or regulation but an industry mandate. Your enterprise must be PCI-compliant if it accepts credit card payments or handles payment card data.
PCI DSS Compliance: Where to Begin
Each PCI DSS requirement has directives and sub-requirements, totaling 281. Only some of these directives pertain to every organization.
To save time, money, and hassle, begin your PCI DSS compliance journey with scoping, determining which requirements and directives are relevant to your enterprise.
Scoping begins with understanding which PCI DSS level your organization belongs to. The higher the level, the more requirements you’ll need to follow.
The Four PCI DSS Compliance Levels
The PCI Security Standards Council (PCI SSC) has established four PCI compliance levels. Your organization’s status depends on how many payment-card transactions you process yearly and which cards you accept:
- PCI Compliance Level 1: More than six million Visa, Mastercard, or Discover or more than 2.5 million American Express transactions per year
- PCI Compliance Level 2: More than 1 million to 6 million Visa or Mastercard or more than 50,000 American Express transactions per year
- PCI Compliance Level 3: 20,000 to 1 million Visa or Mastercard transactions, or fewer than 50,000 American Express transactions per year
- PCI Compliance Level 4: Fewer than 20,000 Visa or Mastercard eCommerce transactions per year and fewer than 1 million total Visa or Mastercard credit card transactions, and no data breach or attack that compromised card or cardholder data
Merchants in levels 2, 3, or 4 must complete the PCI DSS Self-Assessment Questionnaire (SAQ) annually and assess their network security every quarter.
Level 1 merchants must:
- File an Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA) or Internal Security Assessor
- Submit the results of quarterly network vulnerability scans by an Approved Scan Vendor (ASV)
- Complete the PCI SSC Attestation of Compliance (AOC) form
What are the Benefits of PCI DSS Compliance?
Being PCI compliant has various advantages for e-commerce businesses:
- Cut down on data leaks by securing client credit card data from online attacks.
- Avoid paying fines for security flaws or data breaches.
- Enhance customers’ brand reputation and trust.
- Protect your clients and your company while advancing global payment card security solutions.
- Better equip your organization to comply with other standards like SOX and HIPAA.
PCI compliance is mandated by courts even if not required by legislation. You must safeguard clients’ private financial information when you take card payments.
PCI DSS Compliance Checklist
The PCI DSS requirements fall into six categories. Here are the categories, the requirements under them, and a brief explanation of what compliance with each entails.
Build and Maintain a Secure Network
- 1.Install and maintain a firewall to protect cardholder data:
- Review firewall configurations every six months, at minimum.
- Test changes and identify system connections that might affect cardholder data.
- Deny traffic from “untrusted” networks and hosts.
- Block public access to the cardholder data environment.
- Install firewalls on every mobile or employee-owned computer that connects to your network.
- 2.Do not use vendor-supplied defaults for system passwords and other security parameters:
- Change defaults before installing systems, including wireless devices.
- Ensure software settings address known security vulnerabilities and meet industry requirements.
- Encrypt everything.
- Ensure hosting providers protect your information and cardholders’ sensitive data.
Protect Cardholder Data
Cardholder data includes any information printed, processed, transmitted, or stored in any form on a payment card.
- 1.Protect Stored Cardholder Data:
- Do not store authentication information, even if encrypted.
- Do not display Primary Account Numbers (PAN).
- Mask PANs wherever they are held and minimize storage locations.
- Protect cryptographic keys.
- Document all encryption usage and protect cryptographic keys.
- 2.Encrypt Transmission of Cardholder Data Across Open, Public Networks:
- Use SSL/TLS encryption when transmitting data. Do not use outdated protocols like WEP.
- Always encrypt PANs before transmission.
Maintain a Vulnerability Management Program
- 1.Use and Regularly Update Antivirus Software:
- Continually update antivirus software and install patches promptly.
- Install antivirus and anti-malware on all systems, especially personal ones.
- Ensure antivirus software is up-to-date, actively used, and generates logs for auditors.
- 2.Develop and Maintain Secure Systems and Applications:
- Install vendor-supplied security updates within one month of release.
- Use alert systems to identify new vulnerabilities.
- Use PCI DSS best practices when developing new systems.
- Follow policies and procedures for control changes.
- Meet coding guidelines for web-based applications to identify vulnerabilities.
- Protect web-facing applications against known attacks by reviewing code and installing necessary firewalls.
Implement Strong Access Control Measures
- 1.Restrict Access to Cardholder Data by Business Need-to-Know:
- Limit access to system components to only those who need them.
- Provide each user only what they need to perform their job.
- Control user access to cardholder data.
- 2.Assign a Unique ID to Each Person with Computer Access:
- Limit access based on job necessity.
- Use at least one type of authentication, preferably more.
- Provide remote workers with two-factor or multi-factor authentication.
- Encrypt password information.
- Ensure proper authentication and password management for all non-consumers.
- 3.Restrict Physical Access to Cardholder Data:
- Place controls and monitoring on access to physical information.
- Create procedures for who is allowed in each area, including employees and visitors.
- Authorize visitors with expiring physical tokens.
- Keep a visitor log.
- Ensure all media backups are off-site and protected.
- Lock up paper and electronic media containing cardholder data.
- Control the use of media containing cardholder data.
- Provide management with information and approval of data location and movement.
- Strictly control storage and access to media.
- Destroy data when no longer needed using established protocols.
Regularly Monitor and Test Networks
- 1.Track and Monitor All Access to Network Resources and Cardholder Data:
- Provide users with individual access rights and monitor their access, especially administrators.
- Develop automated audit trails to track entry to your information environment.
- Synchronize all clocks.
- Lockdown audit trails to prevent tampering.
- Review logs daily.
- Retain audit documentation for at least one year and immediate history for at least three months.
- 2.Regularly Test Security Systems and Processes:
- Use wireless IDS/IPS to identify wireless devices at least quarterly.
- Scan for internal and external vulnerabilities quarterly or after significant network changes.
- Perform external and internal penetration testing at least once a year or after major upgrades.
- Monitor traffic into and out of your cardholder data environment.
- Deploy alerts to IT about unauthorized modification of system files or content files.
Maintain an Information Security Policy
- 1.Maintain a Policy that Addresses Information Security:
- Create and distribute an information security policy to all users; verify all have read it.
- Review the policy annually to ensure it protects your current Cardholder Data Environment (CDE).
- Assign daily security duties that meet PCI requirements.
- Write procedures for employee and contractor access to company technology and information, and share with affected users.
- Clearly define the rights and responsibilities of employees and contractors.
Let ZenGRC Help You Maintain PCI DSS Compliance
The penalties for PCI DSS non-compliance can be severe. If you fail to meet the requirements, the PCI SSC council could revoke your rights to process payment cards.
Following the rules is the best way to keep those card-processing rights intact. Using software to automate your compliance, alert you to issues, and document your efforts can help you pass certification audits.
ZenGRC software:
- Probes your system and networks to determine compliance with regulatory and industry frameworks
- Displays findings on a dashboard with checklists
- Tracks workflows for compliance efforts
- Helps generate vendor questionnaires and compiles responses
- Alerts you in real-time to compliance gaps
- Conducts unlimited self-audits
- Documents all compliance activities in a central repository for audit trails
Compliance with PCI DSS needn’t be a hassle. Contact ZenGRC to schedule a demo and embark on the journey to PCI DSS compliance.