PCI compliance requirement 8: Unique IDs
Date: Jun 01, 2009
- Give everyone with acess to cardholder data a unique ID
- Authenticate use of that ID using a strong password or two factors
Ed and Diana also review common questions that they hear when doing their QSA work, like "What about shared IDs?" or "Does a PIN and a password count as two-factor authentication?"
Watch the rest of the PCI compliance requirement videos.
Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:
Security Management Strategies for the CIO

