Secure System Configuration Standards
What this control requires
Apply industry-accepted system hardening standards to all CDE system components before deployment. Remove all default passwords and unnecessary services, protocols, and functionality. Maintain configuration standards for each system type. Review configurations quarterly and after significant changes.
Other PCI DSS controls
PCI_DSS-CTRL-001 - Daily safeguarding reconciliationPCI_DSS-CTRL-002 - Critical ICT incident reportingPCI_DSS-CTRL-003 - GDPR breach notification workflowPCI_DSS-CTRL-004 - AML suspicious transaction monitoringPCI_DSS-CTRL-005 - Quarterly PCI vulnerability assessmentPCI_DSS-CTRL-006 - Outsourcing provider oversightPCI_DSS-CTRL-007 - DORA Register of Information maintenancePCI_DSS-CTRL-008 - CTIF suspicious activity escalationPCI_DSS-CTRL-009 - NIS2 cyber resilience testingPCI_DSS-CTRL-010 - Instant payment availability monitoringPCI-AUTH-001 - Implement Strong Access Control for Cardholder DataPCI-ENCRYPT-001 - Protect Stored Cardholder Data with Strong Cryptography