CyberTRIZPEDIA

User Identity and Authentication Controls

Control
PCI-R8-001
Regulation
PCI DSS
Category
technical
Priority
critical
Frequency
quarterly
Type
technical

What this control requires

Implement unique IDs for all users, enforce MFA for all non-console CDE access and all remote access, set minimum 12-character password complexity, lock accounts after 6 failed attempts, automatically lock idle sessions after 15 minutes, and retain authentication audit logs for 12 months.

Other PCI DSS controls