In: Computer Science
1) Describe what is PCI DSS and what are the specific requirements for Applications?
Answer)
PCI DSS is the Payment Card Industry Data Security Standard which
is the set of the security controls and standards which should be
implemented by the businesses to protect the credit card
information and data. This is mandatory for all the businesses and
organizations which handle credit, debit and other cards. Some of
the specific requirements for Applications are:
Installing and maintaining a firewall for protecting cardholder
data.
Not using default passwords on the applications or cards.
Protection of the cardholder's stored data.
Encryption of the data among the public and private networks.
Antivirus software should be installed and regularly updated.
Maintenance of security systems and applications should be
done.
We should restrict the access to the cardholder data by the people
only on a need to know basis.
User unique id should be assigned to every person who logs in tot
he computer.
Physical access to the data should be restricted.
Monitoring the systems, processes and also the access to the
network resources and data stored.
Lastly, we need to have a policy which oversees information
security.