Organizations must track and monitor all access to cardholder data and related network resources – in stores, regional offices, headquarters, and other remote access.
|
Yes, it is well documented that the three (3) tenets for adhering to PCI DSS 2.0 are as follows: |
|
|
Assess - Identifying cardholder data, taking an inventory of your IT assets and business processes for payment card processing, and analyzing them for vulnerabilities that could expose cardholder data. Remediate - Fixing vulnerabilities and not storing cardholder data unless you need it. Report - Compiling and submitting required remediation validation records (if applicable), and submitting compliance reports to the acquiring bank and card. |
|
