From the AVP - 12 Steps for Enterprise Security Compliance
- Install and maintain a firewall, IDS/IPS for data protection
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Classify and then protect stored data
- Encrypt the transmission of cardholder data and sensitive information across public networks
- Use and regularly update antivirus software
- Develop and maintain secure systems and applications
- Restrict access to data by business need-to-know and encrypt highly restricted data in storage
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access (logical and physical) to network resources and cardholder data
- Regularly test and assess security systems and processes
- Maintain a policy that addresses information security
|
|
|