PCI Data Security Standard


Jurisdiction of this law:
International

Type of Rule:
Standard

Popular name:
PCI Data Security Standard

Official name:
The Payment Card Industry Data Security Standard

Other names:
PCI DSS

For more information:
Official Site:
 https://www.pcisecuritystandards.org/tech/index.htm

Text of the standard:
 https://www.pcisecuritystandards.org/tech/download_the_pci_dss.htm




Description:
The PCI DSS version 1.1, a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International, to help facilitate the broad adoption of consistent data security measures on a global basis.

The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data, (definition from
www.pcisecuritystandards.org


Summary of PCI Requirements:

Build and Maintain a Secure Network

Requirement 1: Install and maintain a firewall configuration to protect cardholder data

Requirement 2: Do not use vendor-supplied defaults for system passwords and other
security parameters

Protect Cardholder Data

Requirement 3: Protect stored cardholder data

Requirement 4: Encrypt transmission of cardholder data across open, public networks

Maintain a Vulnerability Management Program

Requirement 5: Use and regularly update anti-virus software

Requirement 6: Develop and maintain secure systems and applications

Implement Strong Access Control Measures

Requirement 7: Restrict access to cardholder data by business need-to-know

Requirement 8: Assign a unique ID to each person with computer access

Requirement 9: Restrict physical access to cardholder data

Regularly Monitor and Test Networks

Requirement 10: Track and monitor all access to network resources and cardholder data

Requirement 11: Regularly test security systems and processes

Maintain an Information Security Policy

Requirement 12: Maintain a policy that addresses information security

You can download the entire standard at
https://www.pcisecuritystandards.org/tech/download_the_pci_dss.htm.
Even if this standard doesn't apply to your organization, its clarity makes it a good document for  discussion of security controls when technical and non-technical resources need to come to an understanding about key concepts


Copyright 2004-2008 The Data Governance Institute, LLC. All Rights Reserved
The site is brought to you in partnership with the Business Intelligence Network



Copyright 2004-2008 The Data Governance Institute, LLC. All Rights Reserved
The site is brought to you in partnership with the Business Intelligence Network

DGI Header
GwenThomas
Data Governance.com
DataGovernance.com is an affiliate of BeyeNETWORK
Home

About Data Governance

Data Laws

- International Rules

- State Laws

- Federal Laws

- Federal Credit Laws

- UK and Canadian Laws

- Privacy Resources

- Caifornia Security Breach Notification Law

- Security Breaches