PCI compliance requirement 8: Unique IDs

PCI compliance requirement 8: Unique IDs

PCI compliance requirement 8: Unique IDs

Date: Jun 01, 2009
Diana Kelley and Ed Moyle of Security Curve review PCI compliance requirement 8: "Assign a unique ID to each person with computer access." To meet PCI compliance Requirement 8, you must:

  • Give everyone with acess to cardholder data a unique ID
  • Authenticate use of that ID using a strong password or two factors

Ed and Diana also review common questions that they hear when doing their QSA work, like "What about shared IDs?" or "Does a PIN and a password count as two-factor authentication?"

Watch the rest of the PCI compliance requirement videos.

Editor's note: This video is based on PCI DSS version 1.1. For updated information on the changes in PCI DSS version 1.2, see the following:

More on PCI Data Security Standard