Req 2 Flashcards
Always change vendor-supplied defaults adn remove or disable unnecessary default accounts before installing a system on the network.
This applica to ALL default passwords including but not limited to those used by operating systems, software that provides security services, application and system accounts, point-of-sale (POS) terminal, payment applications, SImple Network MAnagement Protocol (SNMP) community strings.
Requirement 2.1
For wireless environments connected to the cardholder data environment or transmitting cardholders data, change ALL wireless vendor defaults at installation, including but not limited to default wireless encryption keys, passwords, and SNMP community strings
Requirement 2.1.1
Develop configuration standards for all system components. Assure that these standards address all known security vulnerabilities and are consistent with industry-accepted systems hardening standard may include, but not limited to :
CEnter for Internet Security (CIS)
International Organization for Standardization (ISO)
SysAdmin Audit Network Security (SANS) Institute
National Institute of Standards TEchnology (NIST)
Requirement 2.2
Implement only one primary function per server to prevent functions that require different security levels from co-existing on the same server.
For example. web servers, database servers, and DNS should be implemented on separate servers.
Requirement 2.2.1
Enable only necessary services, protocol, daemon, etc., as required for the function of the system.
Requirement 2.2.2
Implement additional security feature for any required services, protocol, or daemons that are considered to be insecure.
Requirement 2.2.3
Configure system security parameter to prevent misuse.
Requirement 2.2.4
REmove all unnecessary functionality, such as scripts, drivers, features, subsystems, file systems, and unnecessary web servers.
Requirement 2.2.5
Encrypt all non-console administrative access using strong cryptography.
Requirement 2.3
Maintain an inventory of system components that are in scope for PCI DSS.
Requirement 2.4
Ensure that security policies and operational procedures for managing vendor defaults adn other security parameter are documented, in use, and known to all affected parties.
Requirement 2.5
Shared hosting providers must protect each entity hosted environment and cardholder data.
Requirement 2.6