PCI compliance requirement 7: Restrict access

PCI compliance requirement 7: Restrict access

PCI compliance requirement 7: Restrict access

Date: Jun 01, 2009
Diana Kelley and Ed Moyle of Security Curve review PCI compliance requirement 7: "Restrict access to cardholder data by business need-to-know." To meet PCI compliance requirement 7, you must:

  • Have a policy and dcoumented processes that limit who can have access to cardholder data
  • Have systems that enforce the policy

The compliance duo addresses common questions related to PCI compliance requirement 7, like "Do we need an automated access control system?"

Watch the rest of the PCI compliance videos, as Ed and Diana review each particular requirement.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

More on PCI Data Security Standard