The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards formed in 2004 by Visa, MasterCard, Discover Financial Services, JCB International and American Express. Governed by the Payment Card Industry Security Standards Council (PCI SSC), the compliance scheme aims to secure credit and debit card transactions against data theft and fraud.

The 12 Requirements of PCI-DSS in simple terms that all businesses must have.

  1. Install and Configure Firewalls and Network Security.
  2. Change Default passwords and configurations on all systems
  3. Protect stored Cardholder Data
  4. Encrypt Cardholder Data during transmission of information
  5. Install and keep up to date Antivirus Software
  6. Securely develop and maintain systems and websites
  7. Keep all accesses to systems to the least Needed
  8. Keep one user per person and do not use generic accounts
  9. Set up and maintain physical security to protect systems and Cardholder Data
  10. Keep logs for all systems in the Cardholder Data Environment
  11. Execute ASV Scans and Penetration Tests
  12. Create and maintain a Security Policy

Use this tool to find the PCI-DSS Certification Type you need for your business: PCI-DSS