PCI compliance requirement 2: Defaults

PCI compliance requirement 2: Defaults

PCI compliance requirement 2: Defaults

Date: Jun 01, 2009
Diana Kelley and Ed Moyle, co-founders of Security Curve, address PCI compliance requirement 2: "Do not use vendor-supplied defaults for system passwords and other security parameters." PCI compliance requirement 2 calls for:

  • Documentation of a secure configuration, which includes removal of vendor-enabled passwords and unnecessary services
  • Implementation of security features like encryption for administrative connections

Ed and Diana review common PCI questions, including "What should be done about hosting providers?"

Watch the rest of the PCI compliance videos, as the experts continue their advice requirement by requirement.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

More on PCI Data Security Standard