The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store, or transmit credit card information maintain a secure environment.


ControlDescription
Requirement 1 - FirewallsInstall and maintain a firewall configuration to protect cardholder data.
Requirement 2 - DefaultsDo not use vendor-supplied defaults for system passwords and other security parameters.
Requirement 3 - Cardholder DataProtect stored cardholder data.
Requirement 4 - Encrypted TransmissionEncrypt transmission of cardholder data across open, public networks
Requirement 5 - Anti-Virus and MalwareProtect all systems against malware and regularly update anti-virus software or programs.
Requirement 6 - Secure SystemsDevelop and maintain secure systems and applications.
Requirement 7 - Restrict AccessRestrict access to cardholder data by business need to know.
Requirement 8 - Identify AccessIdentify and authenticate access to system components.
Requirement 9 - Physical AccessRestrict physical access to cardholder data.
Requirement 10 - Track AccessTrack and monitor all access to network resources and cardholder data.
Requirement 11 - Test SystemsRegularly test security systems and processes.
Requirement 12 - PolicyMaintain a policy that addresses information security for all personnel.


To View the Compliance Programs available visit Compliance in your Aqua CSPM Console, and select Defaults or Custom to filter the programs displayed, you can also expand the program control details using the Expand Settings toggle.