Implement Strong Access Control for Cardholder Data
What this control requires
Implement MFA for all non-console access to the CDE and all access to the CDE from remote networks. Enforce unique IDs for all users. Implement password complexity requirements (minimum 12 characters). Automatically lock accounts after 6 failed login attempts. Review user access rights quarterly. Maintain access control audit logs for minimum 12 months.
Other PCI DSS controls
PCI_DSS-CTRL-001 - Daily safeguarding reconciliationPCI_DSS-CTRL-002 - Critical ICT incident reportingPCI_DSS-CTRL-003 - GDPR breach notification workflowPCI_DSS-CTRL-004 - AML suspicious transaction monitoringPCI_DSS-CTRL-005 - Quarterly PCI vulnerability assessmentPCI_DSS-CTRL-006 - Outsourcing provider oversightPCI_DSS-CTRL-007 - DORA Register of Information maintenancePCI_DSS-CTRL-008 - CTIF suspicious activity escalationPCI_DSS-CTRL-009 - NIS2 cyber resilience testingPCI_DSS-CTRL-010 - Instant payment availability monitoringPCI-ENCRYPT-001 - Protect Stored Cardholder Data with Strong CryptographyPCI-LOG-001 - Implement Audit Log Management for CDE