Requirements for all organisations
The industry standard, PCI DSS, includes 12 key requirements for organisations that accept or processes card payments:
- Install and maintain a firewall configuration to protect data
- Do not use vendor-supplied defaults for passwords or other security parameters
- Protect stored data
- Encrypt the transmission of cardholder data and sensitive information
- Use and regularly update anti-virus software
- Develop and maintain securer systems and applications
- Restrict access to data by business need-to-know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security
Advice for your business – we provide further information for acquiring banks, merchants and service providers.
Downloads and resources – a range of tools and documents relating to Visa’s AIS programme.