PCI DSS
PCI DSS requires businesses to undergo at the least an annual penetration test, system upgrades or during any major infrastructure or code changes.
PCI DSS requires businesses to undergo at the least an annual penetration test, system upgrades or during any major infrastructure or code changes.
Payment Card Industry Data Security Standard, better known as PCI DSS, is setup and enforced by the PCI Council consisting of American Express, Visa, Mastercard , JCB and Discover organisations.
This standard defines a set of requirements designed for organisations participating in accepting or processing credit card payments to protect customer card data. If a business is involved in credit card payments, whether that's online, over the phone, using PoS, PCI DSS applies to the business.
In order to be compliant, apart from audit requirements, technical PCI DSS audit must be done at least annualy, and should cover areas such as data protection, authentication, access management, encryption.
Defendza can help your business to implement and validate controls required to adhere to PCI DSS requirements detailed below.
Whether your business falls into self-assessment or third party audit, it's mandatory to adhere to six key objectives with total of 12 requirements as listed in the PCI DSS 3.2 guidance
Requirement 12: Maintain a policy that addresses information security for all perosnnel
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Requirement 7: Restrict access to cardholder data by business need to know
Requirement 8: Identify and authenticate access to system components
Requirement 9: Restrict physical access to cardholder data
Requirement 5: Protect all systems against malware and regularly update anti-virus software or programs
Requirement 6: Develop and maintain secure systems and applications
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
Requirement 1: Install and maintan a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
With strong experience and skill-set, Defendza have been helping businesses remain compliant by exceeding their expectations. Both our assessment and managed service offerings are avaialble for no obligation discussions to gain insight into your business objectives and the compliance requirements. Our PCI DSS services include: