Are merchants required to use only strong user accounts and passwords as part of being PCI-DSS compliant?
Yes, merchants are required to use passwords that are at least seven characters in length and consist of at least 3 of the following 4 character types: (upper case letters, lower case letters, numbers, symbols). Merchants are also required to change their passwords at least once every 90 days, and to immediately disable or delete any access credentials for any users who leave the organization or change jobs and no longer require access to the payment processing application.
Related Questions
- When an agencys users migrate, do the administrators need to change passwords for the user accounts and create accounts for every user?
- Are merchants required to use only strong user accounts and passwords as part of being PCI-DSS compliant?
- Can I copy Secure Access accounts, user names and passwords from one G630 to another?