SlideShare ist ein Scribd-Unternehmen logo
1 von 17
PCI Password Compliance
PCI Password Compliance
• What is PCI Compliance
• PCI Password Regulations
• nFront Password Filter Benefits
What is PCI Compliance
Payment Card Industry (PCI) Compliance is
a set of security standards that were
created by the major credit card companies
to protect their customers from increasing
identity theft and security breaches.
PCI Password Requirements


8.5.3 Set first-time passwords to a unique value for each user and
change immediately after the first use.



8.5.8 Do not use group, shared, or generic accounts and
passwords.



8.5.9 Change user passwords at least every 90 days.



8.5.10 Require a minimum password length of at least seven
characters.



8.5.11 Use passwords containing both numeric and alphabetic
characters.



8.5.12 Do not allow an individual to submit a new password that is
the same as any of the previous four passwords.
First Time Passwords
8.5.3 Set first-time passwords to a unique value
for each user and change immediately after the
first use.
 Do not set first time passwords to something simple like the user’s
last name
 Follow up to make sure the user actually logs on and changes their
password
 If the person never logs on the account could sit on the network
awaiting an easy hacking attempt
 Consider our nFront Account Disabler product to disable dormant or
unused accounts
No shared accounts
8.5.8 Do not use group, shared, or generic
accounts and passwords.
 Every administrator and person should have separate user
accounts
 Ideally, administrators should have 2 accounts: one regular user
account and one with administrative privileges
 Shared accounts provide no unique audit trail. Malware or
viruses can destroy or compromise any data accessible by the
shared account
 The built-in administrator account should be used for
emergencies only
Change Passwords Often

8.5.9

Change user passwords at least every 90 days.
Minimum Password Length

8.5.10

Require a minimum password length of at least
seven characters.
Include Numbers in Passwords

8.5.11

Use passwords containing both numeric and
alphabetic characters.
Password Repetition
Windows - Good

8.5.12

nFront - Even Better

Do not allow an individual to submit a new
password that is the same as any of the previous four
passwords.
What is nFront Password Filter
 nFront Password Filter is a password policy
enforcement solution that provides multiple,
granular password policies for Windows domains.

 The standard Windows password policy cannot
meet most industry compliance requirements.
Without nFront Password Filter your network can
allow weak passwords that are an easy target for
hackers and malware.
nFront Password Filter Benefits
nFront Password Filter options exceed PCI Requirements

 One checkbox to meet minimum PCI password requirements
 Up to 6 different granular password policies in one Windows
Domain

 A dictionary option to prevent millions of common passwords
is less than one second
 An optional client to clearly show the password rules and an
improved failure message
One Step Compliance

nFront Password Filter provides features
that Windows cannot - such as one
step PCI Compliance.
Multiple Policies

Create up to 6 different password policies
with each policy targeting one or more
security groups or OUs.
Prevent Common Passwords

Optional nFront features not possible
with standard Windows policies:
• Customizable dictionary check
• Client with strength meter
• Better failure message
nFront Password Filter Benefits
Fill out SAQs faster with the assurance that
you are PCI DSS compliant with a password
filter on your network.
Better security against password
hacking/cracking.
From the nFront Team, Thank You
For questions regarding nFront Security
products or compliance please visit
nFrontSecurity.com

Weitere ähnliche Inhalte

Ähnlich wie PCI Password Policy Compliance

8 passwordsecurity
8 passwordsecurity8 passwordsecurity
8 passwordsecurity
richarddxd
 
Edge overview 5 14
Edge overview 5 14Edge overview 5 14
Edge overview 5 14
Lloyd Owens
 

Ähnlich wie PCI Password Policy Compliance (20)

Windows 10 IoT Buyer's Guide
Windows 10 IoT Buyer's GuideWindows 10 IoT Buyer's Guide
Windows 10 IoT Buyer's Guide
 
D3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access ControlD3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access Control
 
presentation slides
presentation slidespresentation slides
presentation slides
 
IRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key OrderIRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key Order
 
presentation slides
presentation slidespresentation slides
presentation slides
 
Cmpc product update(cp) feb '09-edited
Cmpc product update(cp)   feb '09-editedCmpc product update(cp)   feb '09-edited
Cmpc product update(cp) feb '09-edited
 
Plone OTP
Plone OTPPlone OTP
Plone OTP
 
D3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize SecurityD3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize Security
 
Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020
 
Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...
 
Don't Pick the lock
Don't Pick the lockDon't Pick the lock
Don't Pick the lock
 
Sever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple PasswordsSever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple Passwords
 
R2D2- Personal assistant on android.
R2D2- Personal assistant on android.R2D2- Personal assistant on android.
R2D2- Personal assistant on android.
 
8 passwordsecurity
8 passwordsecurity8 passwordsecurity
8 passwordsecurity
 
riteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminarriteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminar
 
CIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.comCIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.com
 
Edge overview 5 14
Edge overview 5 14Edge overview 5 14
Edge overview 5 14
 
Cypress Best Pratices for Test Automation
Cypress Best Pratices for Test AutomationCypress Best Pratices for Test Automation
Cypress Best Pratices for Test Automation
 
Application Architecture
Application ArchitectureApplication Architecture
Application Architecture
 
Licenses, Contributions, Support or the lack thereof
Licenses, Contributions, Support or the lack thereofLicenses, Contributions, Support or the lack thereof
Licenses, Contributions, Support or the lack thereof
 

Kürzlich hochgeladen

VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
dipikadinghjn ( Why You Choose Us? ) Escorts
 
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
dipikadinghjn ( Why You Choose Us? ) Escorts
 
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
dipikadinghjn ( Why You Choose Us? ) Escorts
 

Kürzlich hochgeladen (20)

falcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunitiesfalcon-invoice-discounting-unlocking-prime-investment-opportunities
falcon-invoice-discounting-unlocking-prime-investment-opportunities
 
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
VIP Call Girl Service Andheri West ⚡ 9920725232 What It Takes To Be The Best ...
 
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
(INDIRA) Call Girl Mumbai Call Now 8250077686 Mumbai Escorts 24x7
 
Vasai-Virar Fantastic Call Girls-9833754194-Call Girls MUmbai
Vasai-Virar Fantastic Call Girls-9833754194-Call Girls MUmbaiVasai-Virar Fantastic Call Girls-9833754194-Call Girls MUmbai
Vasai-Virar Fantastic Call Girls-9833754194-Call Girls MUmbai
 
Top Rated Pune Call Girls Shikrapur ⟟ 6297143586 ⟟ Call Me For Genuine Sex S...
Top Rated  Pune Call Girls Shikrapur ⟟ 6297143586 ⟟ Call Me For Genuine Sex S...Top Rated  Pune Call Girls Shikrapur ⟟ 6297143586 ⟟ Call Me For Genuine Sex S...
Top Rated Pune Call Girls Shikrapur ⟟ 6297143586 ⟟ Call Me For Genuine Sex S...
 
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...Booking open Available Pune Call Girls Talegaon Dabhade  6297143586 Call Hot ...
Booking open Available Pune Call Girls Talegaon Dabhade 6297143586 Call Hot ...
 
Top Rated Pune Call Girls Aundh ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Aundh ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Aundh ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Aundh ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure serviceWhatsApp 📞 Call : 9892124323  ✅Call Girls In Chembur ( Mumbai ) secure service
WhatsApp 📞 Call : 9892124323 ✅Call Girls In Chembur ( Mumbai ) secure service
 
Diva-Thane European Call Girls Number-9833754194-Diva Busty Professional Call...
Diva-Thane European Call Girls Number-9833754194-Diva Busty Professional Call...Diva-Thane European Call Girls Number-9833754194-Diva Busty Professional Call...
Diva-Thane European Call Girls Number-9833754194-Diva Busty Professional Call...
 
Top Rated Pune Call Girls Dighi ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Dighi ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Dighi ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Dighi ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Enjoy Night⚡Call Girls Patel Nagar Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Patel Nagar Delhi >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Patel Nagar Delhi >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Patel Nagar Delhi >༒8448380779 Escort Service
 
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
VIP Independent Call Girls in Andheri 🌹 9920725232 ( Call Me ) Mumbai Escorts...
 
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
VIP Independent Call Girls in Mumbai 🌹 9920725232 ( Call Me ) Mumbai Escorts ...
 
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Koregaon Park Call Me 7737669865 Budget Friendly No Advance Booking
 
Solution Manual for Principles of Corporate Finance 14th Edition by Richard B...
Solution Manual for Principles of Corporate Finance 14th Edition by Richard B...Solution Manual for Principles of Corporate Finance 14th Edition by Richard B...
Solution Manual for Principles of Corporate Finance 14th Edition by Richard B...
 
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
TEST BANK For Corporate Finance, 13th Edition By Stephen Ross, Randolph Weste...
 
Top Rated Pune Call Girls Pashan ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated  Pune Call Girls Pashan ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...Top Rated  Pune Call Girls Pashan ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated Pune Call Girls Pashan ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
 
Business Principles, Tools, and Techniques in Participating in Various Types...
Business Principles, Tools, and Techniques  in Participating in Various Types...Business Principles, Tools, and Techniques  in Participating in Various Types...
Business Principles, Tools, and Techniques in Participating in Various Types...
 
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...
 
Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.Gurley shaw Theory of Monetary Economics.
Gurley shaw Theory of Monetary Economics.
 

PCI Password Policy Compliance

  • 2. PCI Password Compliance • What is PCI Compliance • PCI Password Regulations • nFront Password Filter Benefits
  • 3. What is PCI Compliance Payment Card Industry (PCI) Compliance is a set of security standards that were created by the major credit card companies to protect their customers from increasing identity theft and security breaches.
  • 4. PCI Password Requirements  8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.  8.5.8 Do not use group, shared, or generic accounts and passwords.  8.5.9 Change user passwords at least every 90 days.  8.5.10 Require a minimum password length of at least seven characters.  8.5.11 Use passwords containing both numeric and alphabetic characters.  8.5.12 Do not allow an individual to submit a new password that is the same as any of the previous four passwords.
  • 5. First Time Passwords 8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.  Do not set first time passwords to something simple like the user’s last name  Follow up to make sure the user actually logs on and changes their password  If the person never logs on the account could sit on the network awaiting an easy hacking attempt  Consider our nFront Account Disabler product to disable dormant or unused accounts
  • 6. No shared accounts 8.5.8 Do not use group, shared, or generic accounts and passwords.  Every administrator and person should have separate user accounts  Ideally, administrators should have 2 accounts: one regular user account and one with administrative privileges  Shared accounts provide no unique audit trail. Malware or viruses can destroy or compromise any data accessible by the shared account  The built-in administrator account should be used for emergencies only
  • 7. Change Passwords Often 8.5.9 Change user passwords at least every 90 days.
  • 8. Minimum Password Length 8.5.10 Require a minimum password length of at least seven characters.
  • 9. Include Numbers in Passwords 8.5.11 Use passwords containing both numeric and alphabetic characters.
  • 10. Password Repetition Windows - Good 8.5.12 nFront - Even Better Do not allow an individual to submit a new password that is the same as any of the previous four passwords.
  • 11. What is nFront Password Filter  nFront Password Filter is a password policy enforcement solution that provides multiple, granular password policies for Windows domains.  The standard Windows password policy cannot meet most industry compliance requirements. Without nFront Password Filter your network can allow weak passwords that are an easy target for hackers and malware.
  • 12. nFront Password Filter Benefits nFront Password Filter options exceed PCI Requirements  One checkbox to meet minimum PCI password requirements  Up to 6 different granular password policies in one Windows Domain  A dictionary option to prevent millions of common passwords is less than one second  An optional client to clearly show the password rules and an improved failure message
  • 13. One Step Compliance nFront Password Filter provides features that Windows cannot - such as one step PCI Compliance.
  • 14. Multiple Policies Create up to 6 different password policies with each policy targeting one or more security groups or OUs.
  • 15. Prevent Common Passwords Optional nFront features not possible with standard Windows policies: • Customizable dictionary check • Client with strength meter • Better failure message
  • 16. nFront Password Filter Benefits Fill out SAQs faster with the assurance that you are PCI DSS compliant with a password filter on your network. Better security against password hacking/cracking.
  • 17. From the nFront Team, Thank You For questions regarding nFront Security products or compliance please visit nFrontSecurity.com