What are the requirements for PCI DSS?
There are twelve requirements falling into 6 categories: • Build and maintain a secure network: Install and maintain a firewall and use unique, high-security passwords with special care to replace default passwords. • Protect cardholder data: Whenever possible, do not store cardholder data. If there is a business need, you must protect this data. You must also encrypt any data passed across public networks, including your shopping cart and web-hosting providers as well when communicating with customers. • Maintain a vulnerability management program: Use an anti-virus software program and keep it up date. Develop and maintain secure operating systems and payment applications. Ensure the anti-virus software applications you use are compliant (see www.visa.com/pabp). • Implement strong access control measures: Access, both electronic and physical access, to cardholder data should be on a “need-to-know” basis. Ensure those people with access have a unique ID and password for electronic acc