The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures designed to optimize the security of credit, debit and cash card transactions and protect cardholders against misuse of their personal information. PCI DSS was created in 2004 by five major credit card companies: Visa, Mastercard, Discover, JCB and American Express.
The primary goal of PCI DSS is to safeguard and optimize the security of sensitive cardholder data, such as credit card numbers, expiration dates and security codes. The standard’s security controls help businesses minimize the risk of data breaches, fraud and identity theft.
The 12 Requirements of PCI DSS
The PCI Security Standards Council (PCI SSC) has established 12 specific requirements that organizations must meet to be PCI DSS-compliant:
1. Install and maintain a firewall configuration to protect cardholder data.
2. Do not use vendor-supplied defaults for system passwords and other security parameters.
3. Protect stored cardholder data.
4. Encrypt transmission of cardholder data across open, public networks.
5. Protect all systems against malware and regularly update anti-virus software or programs.
6. Develop and maintain secure systems and applications.
7. Restrict access to cardholder data by business need-to-know.
8. Identify and authenticate access to system components.
9. Restrict physical access to cardholder data.
10. Track and monitor all access to network resources and cardholder data.
11. Regularly test security systems and processes.
12. Maintain a policy that addresses information security for all personnel.