Requirement 1-12 Flashcards
Theme 1
Build and Maintain Secured Network
Theme 2
Protect Cardholder Data
Theme 3
Maintain a Vulnerability Management Program
Theme 4
Implement Access Controls Measure
Theme 5
Regularly Monitor and Test Network
Theme 6
Maintain Information Security Policies
Build and Maintain Secured Network (Theme 1)
Firewall Management (Req 1)
Vendor Defaults (Req 2)
Protect Cardholder Data (Theme 2)
Data Protection (Req 3)
Data Transmission and Encryption (Req 4)
Maintain a Vulnerability Management Program (Theme 3)
Anti-virus Controls (Req 5)
Systems and Applications Security (Req 6)
Implement Access Controls Measures
Data Access Controls (Req 7)
Personal Access Controls (Req 8)
Physical Access Controls (Req 9)
Data and Network Access Controls (Req 10)
Regularly Monitor and Test Network
Security Testing (Req 11)
Maintain Information Security Policies
Information Security Policies (Req 12)
Process of identifying all system components, people, and processes to be included in a PCI DSS assessment.
SCoping
The purpose is to avoid the ability and risk of out-of-scope systems to interact with the Cardholder Data Environment (CDE) systems or impact the CDE security.
Network Segmentation
If the ____________ is implemented correctly, even if the attacker has administrative access to the out-of-scope system, the CDE is not compromised by a segmented out-of-scope system component.
Network Segmentation