User Identity and Authentication Controls
What this control requires
Implement unique IDs for all users, enforce MFA for all non-console CDE access and all remote access, set minimum 12-character password complexity, lock accounts after 6 failed attempts, automatically lock idle sessions after 15 minutes, and retain authentication audit logs for 12 months.
Other PCI DSS controls
PCI_DSS-CTRL-001 - Daily safeguarding reconciliationPCI_DSS-CTRL-002 - Critical ICT incident reportingPCI_DSS-CTRL-003 - GDPR breach notification workflowPCI_DSS-CTRL-004 - AML suspicious transaction monitoringPCI_DSS-CTRL-005 - Quarterly PCI vulnerability assessmentPCI_DSS-CTRL-006 - Outsourcing provider oversightPCI_DSS-CTRL-007 - DORA Register of Information maintenancePCI_DSS-CTRL-008 - CTIF suspicious activity escalationPCI_DSS-CTRL-009 - NIS2 cyber resilience testingPCI_DSS-CTRL-010 - Instant payment availability monitoringPCI-AUTH-001 - Implement Strong Access Control for Cardholder DataPCI-ENCRYPT-001 - Protect Stored Cardholder Data with Strong Cryptography