| Endpoint Security | Web Security | Messaging Security | Datacenter Security | Data Protection | Vulnerability & Threat Mgt | |
| Build & Maintain a Secure Network |
||||||
|---|---|---|---|---|---|---|
| 1. Install and maintain a firewall configuration | ||||||
| 2. Do not use vendor supplied defaults (shared hosting providers) | ||||||
| Protect Cardholder Data | ||||||
| 3. Protect stored cardholder data | ||||||
| 4. Encrypt transmission of cardholder data across open, public networks | ||||||
| Maintain a Vulnerability Protection Program |
||||||
| 5. Use and regularly update antivirus software | ||||||
| 6. Develop and maintain secure systems and applications | ||||||
| Implement Strong Access Measures |
||||||
| 7. Restrict access to data 8. Assign unique IDs 9. Restrict physical data access |
||||||
| Regularly Monitor and Test Networks |
||||||
| 10. Track/monitor access to network resources and cardholder data | ||||||
| 11. Regularly test security systems and processes | ||||||
| Maintain an Information Security Policy |
||||||
| 12. Maintain information security for employees and contractors | ||||||