This involves installing and maintaining a firewall configuration to protect cardholder data and ensuring that vendor-supplied defaults for system passwords and other security parameters are not used.
Access to cardholder data should be restricted to only those individuals whose job requires such access. This involves assigning a unique ID to each person with computer access and restricting physical access to cardholder data.
This includes using and regularly updating anti-virus software or programs and developing and maintaining secure systems and applications.
Organizations must protect stored cardholder data and encrypt transmission of cardholder data across open, public networks.
Organizations must track and monitor all access to network resources and cardholder data and regularly test security systems and processes.
A policy that addresses information security for all personnel should be maintained.
Trust QMet to help you achieve and maintain compliance with PCI DSS standards. Stay informed, stay secure, and let QMet be your partner in safeguarding your cardholder data.