CyberTRIZPEDIA

Secure System Configuration Standards

Control
PCI-R2-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Apply industry-accepted system hardening standards to all CDE system components before deployment. Remove all default passwords and unnecessary services, protocols, and functionality. Maintain configuration standards for each system type. Review configurations quarterly and after significant changes.

Other PCI DSS controls