What is DHCP (Dynamic Host Configuration Protocol)?

What is PCI DSS 12 requirements?

Technology News


What are the PCI DSS 12 requirements?

The PCI DSS 12 requirements are security controls businesses must implement to protect credit card data and comply with the Payment Card Industry Data Security Standard (PCI DSS). The PCI Security Standards Council (SSC) developed and maintains the list of requirements.

Legally, any organization that handles payment cards, including debit and credit cards, must meet each of the PCI DSS 12 requirements directly or through an approved compensating control. Qualified Security Assessors — data security firms that have completed training and certification with the PCI SSC — review proposed compensating controls on a case-by-case basis.

Failure to meet the PCI DSS 12 requirements may result in fines or termination of credit card processing privileges.

The PCI DSS 12 requirements are as follows:

  1. Install and maintain a firewall configuration to protect cardholder data.
  2. Do not use vendor-supplied defaults for system passwords and other security parameters.
  3. Protect stored cardholder data.
  4. Encrypt transmission of cardholder data across open, public networks.
  5. Use and regularly update antivirus software.
  6. Develop and maintain secure systems and applications.
  7. Restrict access to cardholder data by business need-to-know.
  8. Assign a unique ID to each person with computer access.
  9. Restrict physical access to cardholder data.
  10. Track and monitor all access to network resources and cardholder data.
  11. Regularly test security systems and processes.
  12. Maintain a policy that addresses information security.

This was last updated in March 2023



Continue Reading About PCI DSS 12 requirements











Dig Deeper on Compliance