What is PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is a proprietary information security standard comprising technology requirements and process requirements designed to prevent fraud when handling credit card information. All companies who handle credit cards are subject to this standard.
To be PCI DSS compliant, organizations must meet twelve PCI DSS requirements. Reflection aids compliance with requirements 3,4,6,7 and 10.
PCI DSS Requirements | Support | |
---|---|---|
1 | Install and maintain a firewall configuration to protect cardholder data. | |
2 | Do not use vendor-supplied defaults for system passwords and other security parameters. | |
3 | Protect stored cardholder data. | Supported |
4 | Encrypt transmission of cardholder data across open, public networks. | Supported |
5 | Use and regularly update antivirus software. | |
6 | Develop and maintain security systems and applications. | Supported |
7 | Restrict access to cardholder data by business need-to-know. | Supported |
8 | Assign a unique ID to each person with computer access. | |
9 | Restrict physical access to cardholder data. | |
10 | Track and monitor all access to network resources and cardholder data. | Supported |
11 | Regularly test security systems and processes. | |
12 | Maintain a policy that addresses information security. |