C|EH, CISA, CISSP – Information Security Consultant, Pakistan.
17 Aug
Build & Maintain A Secure Network
Requirement 1:Install and maintain a firewall configuration to protect cardholder data.
Requirement 2:Do not use vendor-supplied defaults for system passwords and other security parameters.
Protect Cardholder Data
Requirement 3:Protect stored cardholder data.
Requirement 4:Encrypt transmission of cardholder data across open, public networks.
Maintain A Vulnerability Management Program
Requirement 5:Use and regularly update antivirus software.
Requirement 6:Develop and maintain secure systems and applications.
Implement Strong Access Control Measures
Requirement 7:Restrict access to cardholder data by business need-to-know.
Requirement 8:Assign a unique ID to each person with computer access.
Requirement 9:Restrict physical access to cardholder data.
Regularly Monitor & Test Networks
Requirement 10:Track and monitor all access to network resources and cardholder data.
Requirement 11: Regularly test security systems and processes.Maintain An Information Security Policy
Requirement 12: Maintain a policy that addresses information security.
SOURCE: PCISECURITYSTANDARDS.ORG
18 Jun
The effective date of the new PCI DSS v1.2 standard was October 1, 2008, and the sunset date of the PCI DSS v1.1 was December 31, 2008. Assessments started prior to October 1 will be according to v. 1.1 and can be completed with v. 1.1. For assessments started between October 1 and December 31, either version could be used. For assessments started after December 31, version 1.2 must be used. The Council is not setting a date after which assessments against v. 1.1 will not be accepted since that is a compliance decision that is up to each payment brand. Please check with your acquirer or the payment brands for any final dates by which v. 1.1 assessments must be complete.
Download: pci_dss_v1-2