The information below is from the PCI Security Standards organization and is intended to be a guide to all entities subject to PCI DSS regulations. To achieve PCI DSS compliance, an organization must meet all PCI DSS requirements, regardless of the order in which they are satisfied or whether the organization seeking
compliance follows the PCI DSS Prioritized Approach.
Currently, all merchants are required to be on PCI DSS version 3.2 or 3.2.1 for PCI compliance. As of January 1st, 2019, you’ll need to process credit card validations with at least PCI DSS version 3.2.1. Below is the PCI DSS Compliance Checklist. We recommend that you review it and assess your readiness for the 2019 standards.
- Install and maintain a firewall configuration to protect cardholder data
- Do not use vendor-supplied defaults for system passwords and other
security parameters - Protect stored cardholder data
- Encrypt transmission of cardholder data across open, public networks
- Protect all systems against malware and regularly update anti-virus software or programs
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need-to-know
- Identify and authenticate access to system components
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security for all personnel
You also will need to review and complete the appropriate self-assessment questionnaire (SAQ) provided by the PCI Security Council to ensure you are following best practices of credit card handling and processing, and be able to provide proof of quarterly scanning.
Posted 2019-05-04.