Test Your Knowledge
PCI DSS v4.0 Requirements
The Payment Card Industry Data Security Standard (PCI DSS) applies to any organization that stores, processes, or transmits cardholder data. Version 4.0 introduces a customized approach alongside the traditional defined approach.
Goal 1: Build and Maintain a Secure Network and Systems
Configure and maintain firewalls, routers, and other network security controls to protect cardholder data.
- Document and implement firewall configuration standards
- Restrict inbound/outbound traffic to only that which is necessary
- Prohibit direct public access to cardholder data environment (CDE)
- Install personal firewalls on portable devices
- Document all allowed services, protocols, and ports
Change vendor-supplied defaults and remove/disable unnecessary services.
- Change all vendor-supplied default passwords
- Remove or disable unnecessary default accounts
- Develop configuration standards for all system types
- Enable only necessary services, protocols, daemons
- Implement additional security for insecure services (if required)
Goal 2: Protect Account Data
Minimize data storage, implement retention policies, and protect stored data.
- Keep cardholder data storage to a minimum
- Do not store sensitive authentication data after authorization
- Mask PAN when displayed (first 6 and last 4 digits maximum)
- Render PAN unreadable using encryption, hashing, or truncation
- Document and implement key management procedures
Encrypt transmission of cardholder data across open, public networks.
- Use strong cryptography (TLS 1.2+) for transmission
- Never send unprotected PANs via email, chat, SMS
- Document all transmission security policies
- Use trusted certificates from recognized CAs
Goal 3: Maintain a Vulnerability Management Program
Deploy and maintain anti-malware software and processes.
- Deploy anti-malware on all systems commonly affected
- Ensure anti-malware is kept current and active
- Perform periodic scans and real-time protection
- Maintain audit logs for anti-malware
- Evaluate systems not commonly affected by malware
Identify vulnerabilities and develop software securely.
- Establish process to identify security vulnerabilities
- Install critical security patches within one month
- Develop applications based on secure coding guidelines
- Address common coding vulnerabilities (OWASP)
- Protect public-facing web applications from attacks
Goal 4: Implement Strong Access Control Measures
Limit access to cardholder data on a need-to-know basis.
- Define access needs for each role
- Restrict access based on job responsibilities
- Default deny-all setting for access control systems
- Review access rights at least every 6 months
Assign unique identification and implement strong authentication.
- Assign unique ID to each person with access
- Implement MFA for all access to CDE
- Require minimum 12-character passwords (or 8 with MFA)
- Lock out accounts after 10 failed attempts
- Session timeout after 15 minutes of inactivity
Limit physical access to systems and media containing cardholder data.
- Use facility entry controls for sensitive areas
- Distinguish between onsite personnel and visitors
- Control physical access to network jacks and devices
- Physically secure all media containing cardholder data
- Destroy media when no longer needed
Goal 5: Regularly Monitor and Test Networks
Track and monitor all access to network resources and cardholder data.
- Implement audit trails for all access to cardholder data
- Record user identification, event type, date/time, success/failure
- Review logs daily for critical systems
- Retain audit history for at least one year
- Protect audit trails from unauthorized modification
Regularly test security systems, processes, and software.
- Test for unauthorized wireless access points quarterly
- Run internal and external vulnerability scans quarterly
- Conduct penetration testing annually (or after significant changes)
- Use intrusion-detection/prevention systems
- Deploy change-detection mechanism on critical files
Goal 6: Maintain an Information Security Policy
Establish, publish, maintain, and disseminate a security policy.
- Establish and publish information security policy
- Implement risk assessment process (annually minimum)
- Develop acceptable use policies for critical technologies
- Ensure personnel are aware of responsibilities
- Implement incident response plan
- Conduct security awareness training upon hire and annually
Merchant Compliance Levels
| Level | Annual Transactions | Validation Requirements |
|---|---|---|
| Level 1 | > 6 million | Annual on-site assessment by QSA, quarterly network scans |
| Level 2 | 1-6 million | Annual SAQ, quarterly network scans |
| Level 3 | 20,000-1 million (e-commerce) | Annual SAQ, quarterly network scans |
| Level 4 | < 20,000 (e-commerce) or < 1 million (other) | Annual SAQ, quarterly scans if applicable |
Need Detailed PCI DSS Implementation Guides?
For comprehensive tutorials and compliance guides:
Visit FixTheVuln.com →FixTheVuln Store
Studying for CISSP or CISA?
Structured study planners covering compliance, governance, and risk.
Related Resources
FixTheVuln Store
Studying for CompTIA Security+? Get the Study Planner
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
CompTIA Security+ Planner60+ certifications available — from $5.99