| Home > Strategies for success -- PCI DSS Requirement 8: Assign a unique ID to each person with computer access | |
| Learning Guide: |
|
||
How to pass PCI Requirement 8
Management must make sure that it enforces a policy for aging passwords. As an example, if a company has a policy that states all passwords will be changed every 45 days, they must be able to demonstrate that this actually occurs. Additionally, organizations have to be able to show that there is a repeatable process in place for providing passwords for new employee hires, as well as removing passwords when an employee no longer works for the organization.
Finally, it is crucial that organizations use an enterprise-wide authentication framework that will control how users can securely connect to the network. The framework, which can be built or bought, should not only be used to authenticate users to resources, but can also help limit access to resources based on business requirements. Doing so requires the development of a set of repeatable processes, along with technologies and policies that will protect user identities and data. Limiting users to a "need to know" basis helps to eliminate risk.
'); // -->
|
||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||
|
||||||||||