SlideShare une entreprise Scribd logo
1  sur  17
PCI Password Compliance
PCI Password Compliance
• What is PCI Compliance
• PCI Password Regulations
• nFront Password Filter Benefits
What is PCI Compliance
Payment Card Industry (PCI) Compliance is
a set of security standards that were
created by the major credit card companies
to protect their customers from increasing
identity theft and security breaches.
PCI Password Requirements


8.5.3 Set first-time passwords to a unique value for each user and
change immediately after the first use.



8.5.8 Do not use group, shared, or generic accounts and
passwords.



8.5.9 Change user passwords at least every 90 days.



8.5.10 Require a minimum password length of at least seven
characters.



8.5.11 Use passwords containing both numeric and alphabetic
characters.



8.5.12 Do not allow an individual to submit a new password that is
the same as any of the previous four passwords.
First Time Passwords
8.5.3 Set first-time passwords to a unique value
for each user and change immediately after the
first use.
 Do not set first time passwords to something simple like the user’s
last name
 Follow up to make sure the user actually logs on and changes their
password
 If the person never logs on the account could sit on the network
awaiting an easy hacking attempt
 Consider our nFront Account Disabler product to disable dormant or
unused accounts
No shared accounts
8.5.8 Do not use group, shared, or generic
accounts and passwords.
 Every administrator and person should have separate user
accounts
 Ideally, administrators should have 2 accounts: one regular user
account and one with administrative privileges
 Shared accounts provide no unique audit trail. Malware or
viruses can destroy or compromise any data accessible by the
shared account
 The built-in administrator account should be used for
emergencies only
Change Passwords Often

8.5.9

Change user passwords at least every 90 days.
Minimum Password Length

8.5.10

Require a minimum password length of at least
seven characters.
Include Numbers in Passwords

8.5.11

Use passwords containing both numeric and
alphabetic characters.
Password Repetition
Windows - Good

8.5.12

nFront - Even Better

Do not allow an individual to submit a new
password that is the same as any of the previous four
passwords.
What is nFront Password Filter
 nFront Password Filter is a password policy
enforcement solution that provides multiple,
granular password policies for Windows domains.

 The standard Windows password policy cannot
meet most industry compliance requirements.
Without nFront Password Filter your network can
allow weak passwords that are an easy target for
hackers and malware.
nFront Password Filter Benefits
nFront Password Filter options exceed PCI Requirements

 One checkbox to meet minimum PCI password requirements
 Up to 6 different granular password policies in one Windows
Domain

 A dictionary option to prevent millions of common passwords
is less than one second
 An optional client to clearly show the password rules and an
improved failure message
One Step Compliance

nFront Password Filter provides features
that Windows cannot - such as one
step PCI Compliance.
Multiple Policies

Create up to 6 different password policies
with each policy targeting one or more
security groups or OUs.
Prevent Common Passwords

Optional nFront features not possible
with standard Windows policies:
• Customizable dictionary check
• Client with strength meter
• Better failure message
nFront Password Filter Benefits
Fill out SAQs faster with the assurance that
you are PCI DSS compliant with a password
filter on your network.
Better security against password
hacking/cracking.
From the nFront Team, Thank You
For questions regarding nFront Security
products or compliance please visit
nFrontSecurity.com

Contenu connexe

Similaire à PCI Password Policy Compliance

D3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access ControlD3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access ControlImperva Incapsula
 
IRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key OrderIRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key OrderIRJET Journal
 
Cmpc product update(cp) feb '09-edited
Cmpc product update(cp)   feb '09-editedCmpc product update(cp)   feb '09-edited
Cmpc product update(cp) feb '09-editedRene Torres Visso
 
D3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize SecurityD3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize SecurityImperva Incapsula
 
Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020Alberto González Trastoy
 
Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...ZTech Proje
 
Sever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple PasswordsSever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple PasswordsPortalGuard
 
R2D2- Personal assistant on android.
R2D2- Personal assistant on android.R2D2- Personal assistant on android.
R2D2- Personal assistant on android.Mohd Nazim
 
8 passwordsecurity
8 passwordsecurity8 passwordsecurity
8 passwordsecurityricharddxd
 
riteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminarriteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminarriteSOFT
 
CIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.comCIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.comRobinson068
 
Edge overview 5 14
Edge overview 5 14Edge overview 5 14
Edge overview 5 14Lloyd Owens
 
Cypress Best Pratices for Test Automation
Cypress Best Pratices for Test AutomationCypress Best Pratices for Test Automation
Cypress Best Pratices for Test AutomationKnoldus Inc.
 

Similaire à PCI Password Policy Compliance (20)

Windows 10 IoT Buyer's Guide
Windows 10 IoT Buyer's GuideWindows 10 IoT Buyer's Guide
Windows 10 IoT Buyer's Guide
 
D3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access ControlD3SF17- Using Incap Rules to Customize Your Security and Access Control
D3SF17- Using Incap Rules to Customize Your Security and Access Control
 
presentation slides
presentation slidespresentation slides
presentation slides
 
IRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key OrderIRJET- Three Step Password Verification by using Random Key Order
IRJET- Three Step Password Verification by using Random Key Order
 
presentation slides
presentation slidespresentation slides
presentation slides
 
Cmpc product update(cp) feb '09-edited
Cmpc product update(cp)   feb '09-editedCmpc product update(cp)   feb '09-edited
Cmpc product update(cp) feb '09-edited
 
Plone OTP
Plone OTPPlone OTP
Plone OTP
 
D3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize SecurityD3NY17- Using IncapRules to Customize Security
D3NY17- Using IncapRules to Customize Security
 
Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020Things I wished I knew before building my first WebRTC app - RTE2020
Things I wished I knew before building my first WebRTC app - RTE2020
 
Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...Psdot 6 web based security analysis of opass authentication schemes using mob...
Psdot 6 web based security analysis of opass authentication schemes using mob...
 
Don't Pick the lock
Don't Pick the lockDon't Pick the lock
Don't Pick the lock
 
Sever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple PasswordsSever-based Password Synchronization: Managing Multiple Passwords
Sever-based Password Synchronization: Managing Multiple Passwords
 
R2D2- Personal assistant on android.
R2D2- Personal assistant on android.R2D2- Personal assistant on android.
R2D2- Personal assistant on android.
 
8 passwordsecurity
8 passwordsecurity8 passwordsecurity
8 passwordsecurity
 
riteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminarriteSOFT SYSPRO 7 seminar
riteSOFT SYSPRO 7 seminar
 
CIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.comCIS 312 Success Begins / snaptutorial.com
CIS 312 Success Begins / snaptutorial.com
 
Password Security
Password SecurityPassword Security
Password Security
 
Edge overview 5 14
Edge overview 5 14Edge overview 5 14
Edge overview 5 14
 
Cypress Best Pratices for Test Automation
Cypress Best Pratices for Test AutomationCypress Best Pratices for Test Automation
Cypress Best Pratices for Test Automation
 
Application Architecture
Application ArchitectureApplication Architecture
Application Architecture
 

Dernier

The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...AES International
 
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...Amil baba
 
Gender and caste discrimination in india
Gender and caste discrimination in indiaGender and caste discrimination in india
Gender and caste discrimination in indiavandanasingh01072003
 
Money Forward Integrated Report “Forward Map” 2024
Money Forward Integrated Report “Forward Map” 2024Money Forward Integrated Report “Forward Map” 2024
Money Forward Integrated Report “Forward Map” 2024Money Forward
 
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...Amil baba
 
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.ppt
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.pptAnyConv.com__FSS Advance Retail & Distribution - 15.06.17.ppt
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.pptPriyankaSharma89719
 
What is sip and What are its Benefits in 2024
What is sip and What are its Benefits in 2024What is sip and What are its Benefits in 2024
What is sip and What are its Benefits in 2024prajwalgopocket
 
The Inspirational Story of Julio Herrera Velutini - Global Finance Leader
The Inspirational Story of Julio Herrera Velutini - Global Finance LeaderThe Inspirational Story of Julio Herrera Velutini - Global Finance Leader
The Inspirational Story of Julio Herrera Velutini - Global Finance LeaderArianna Varetto
 
Financial Preparation for Millennia.pptx
Financial Preparation for Millennia.pptxFinancial Preparation for Millennia.pptx
Financial Preparation for Millennia.pptxsimon978302
 
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书rnrncn29
 
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...Amil baba
 
Global Economic Outlook, 2024 - Scholaride Consulting
Global Economic Outlook, 2024 - Scholaride ConsultingGlobal Economic Outlook, 2024 - Scholaride Consulting
Global Economic Outlook, 2024 - Scholaride Consultingswastiknandyofficial
 
Liquidity Decisions in Financial management
Liquidity Decisions in Financial managementLiquidity Decisions in Financial management
Liquidity Decisions in Financial managementshrutisingh143670
 
2024-04-09 - Pension Playpen roundtable - slides.pptx
2024-04-09 - Pension Playpen roundtable - slides.pptx2024-04-09 - Pension Playpen roundtable - slides.pptx
2024-04-09 - Pension Playpen roundtable - slides.pptxHenry Tapper
 
Introduction to Health Economics Dr. R. Kurinji Malar.pptx
Introduction to Health Economics Dr. R. Kurinji Malar.pptxIntroduction to Health Economics Dr. R. Kurinji Malar.pptx
Introduction to Health Economics Dr. R. Kurinji Malar.pptxDrRkurinjiMalarkurin
 
Kempen ' UK DB Endgame Paper Apr 24 final3.pdf
Kempen ' UK DB Endgame Paper Apr 24 final3.pdfKempen ' UK DB Endgame Paper Apr 24 final3.pdf
Kempen ' UK DB Endgame Paper Apr 24 final3.pdfHenry Tapper
 
Banking: Commercial and Central Banking.pptx
Banking: Commercial and Central Banking.pptxBanking: Commercial and Central Banking.pptx
Banking: Commercial and Central Banking.pptxANTHONYAKINYOSOYE1
 
Stock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfStock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfMichael Silva
 
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...Amil baba
 
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...beulahfernandes8
 

Dernier (20)

The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...
 
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
Uae-NO1 Black Magic Specialist In Lahore Black magic In Pakistan Kala Ilam Ex...
 
Gender and caste discrimination in india
Gender and caste discrimination in indiaGender and caste discrimination in india
Gender and caste discrimination in india
 
Money Forward Integrated Report “Forward Map” 2024
Money Forward Integrated Report “Forward Map” 2024Money Forward Integrated Report “Forward Map” 2024
Money Forward Integrated Report “Forward Map” 2024
 
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...
Uae-NO1 Rohani Amil In Islamabad Amil Baba in Rawalpindi Kala Jadu Amil In Ra...
 
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.ppt
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.pptAnyConv.com__FSS Advance Retail & Distribution - 15.06.17.ppt
AnyConv.com__FSS Advance Retail & Distribution - 15.06.17.ppt
 
What is sip and What are its Benefits in 2024
What is sip and What are its Benefits in 2024What is sip and What are its Benefits in 2024
What is sip and What are its Benefits in 2024
 
The Inspirational Story of Julio Herrera Velutini - Global Finance Leader
The Inspirational Story of Julio Herrera Velutini - Global Finance LeaderThe Inspirational Story of Julio Herrera Velutini - Global Finance Leader
The Inspirational Story of Julio Herrera Velutini - Global Finance Leader
 
Financial Preparation for Millennia.pptx
Financial Preparation for Millennia.pptxFinancial Preparation for Millennia.pptx
Financial Preparation for Millennia.pptx
 
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书
『澳洲文凭』买科廷大学毕业证书成绩单办理澳洲Curtin文凭学位证书
 
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...
NO1 Certified kala jadu karne wale ka contact number kala jadu karne wale bab...
 
Global Economic Outlook, 2024 - Scholaride Consulting
Global Economic Outlook, 2024 - Scholaride ConsultingGlobal Economic Outlook, 2024 - Scholaride Consulting
Global Economic Outlook, 2024 - Scholaride Consulting
 
Liquidity Decisions in Financial management
Liquidity Decisions in Financial managementLiquidity Decisions in Financial management
Liquidity Decisions in Financial management
 
2024-04-09 - Pension Playpen roundtable - slides.pptx
2024-04-09 - Pension Playpen roundtable - slides.pptx2024-04-09 - Pension Playpen roundtable - slides.pptx
2024-04-09 - Pension Playpen roundtable - slides.pptx
 
Introduction to Health Economics Dr. R. Kurinji Malar.pptx
Introduction to Health Economics Dr. R. Kurinji Malar.pptxIntroduction to Health Economics Dr. R. Kurinji Malar.pptx
Introduction to Health Economics Dr. R. Kurinji Malar.pptx
 
Kempen ' UK DB Endgame Paper Apr 24 final3.pdf
Kempen ' UK DB Endgame Paper Apr 24 final3.pdfKempen ' UK DB Endgame Paper Apr 24 final3.pdf
Kempen ' UK DB Endgame Paper Apr 24 final3.pdf
 
Banking: Commercial and Central Banking.pptx
Banking: Commercial and Central Banking.pptxBanking: Commercial and Central Banking.pptx
Banking: Commercial and Central Banking.pptx
 
Stock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdfStock Market Brief Deck FOR 4/17 video.pdf
Stock Market Brief Deck FOR 4/17 video.pdf
 
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...
Uae-NO1 Pakistani Amil Baba Real Amil baba In Pakistan Najoomi Baba in Pakist...
 
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...
Unveiling Poonawalla Fincorp’s Phenomenal Performance Under Abhay Bhutada’s L...
 

PCI Password Policy Compliance

  • 2. PCI Password Compliance • What is PCI Compliance • PCI Password Regulations • nFront Password Filter Benefits
  • 3. What is PCI Compliance Payment Card Industry (PCI) Compliance is a set of security standards that were created by the major credit card companies to protect their customers from increasing identity theft and security breaches.
  • 4. PCI Password Requirements  8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.  8.5.8 Do not use group, shared, or generic accounts and passwords.  8.5.9 Change user passwords at least every 90 days.  8.5.10 Require a minimum password length of at least seven characters.  8.5.11 Use passwords containing both numeric and alphabetic characters.  8.5.12 Do not allow an individual to submit a new password that is the same as any of the previous four passwords.
  • 5. First Time Passwords 8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.  Do not set first time passwords to something simple like the user’s last name  Follow up to make sure the user actually logs on and changes their password  If the person never logs on the account could sit on the network awaiting an easy hacking attempt  Consider our nFront Account Disabler product to disable dormant or unused accounts
  • 6. No shared accounts 8.5.8 Do not use group, shared, or generic accounts and passwords.  Every administrator and person should have separate user accounts  Ideally, administrators should have 2 accounts: one regular user account and one with administrative privileges  Shared accounts provide no unique audit trail. Malware or viruses can destroy or compromise any data accessible by the shared account  The built-in administrator account should be used for emergencies only
  • 7. Change Passwords Often 8.5.9 Change user passwords at least every 90 days.
  • 8. Minimum Password Length 8.5.10 Require a minimum password length of at least seven characters.
  • 9. Include Numbers in Passwords 8.5.11 Use passwords containing both numeric and alphabetic characters.
  • 10. Password Repetition Windows - Good 8.5.12 nFront - Even Better Do not allow an individual to submit a new password that is the same as any of the previous four passwords.
  • 11. What is nFront Password Filter  nFront Password Filter is a password policy enforcement solution that provides multiple, granular password policies for Windows domains.  The standard Windows password policy cannot meet most industry compliance requirements. Without nFront Password Filter your network can allow weak passwords that are an easy target for hackers and malware.
  • 12. nFront Password Filter Benefits nFront Password Filter options exceed PCI Requirements  One checkbox to meet minimum PCI password requirements  Up to 6 different granular password policies in one Windows Domain  A dictionary option to prevent millions of common passwords is less than one second  An optional client to clearly show the password rules and an improved failure message
  • 13. One Step Compliance nFront Password Filter provides features that Windows cannot - such as one step PCI Compliance.
  • 14. Multiple Policies Create up to 6 different password policies with each policy targeting one or more security groups or OUs.
  • 15. Prevent Common Passwords Optional nFront features not possible with standard Windows policies: • Customizable dictionary check • Client with strength meter • Better failure message
  • 16. nFront Password Filter Benefits Fill out SAQs faster with the assurance that you are PCI DSS compliant with a password filter on your network. Better security against password hacking/cracking.
  • 17. From the nFront Team, Thank You For questions regarding nFront Security products or compliance please visit nFrontSecurity.com