PCI DSS Part 5.1 – Requirements in Depth

Virtual Practice Lab
Practice Test
PCI DSS Part 5.1 – Requirements in Depth

This video is the first of two parts which cover the 12 elements or requirements of the PCI DSS introduced in the earlier videos. Requirements 1-6 are:

  1. Firewall and router configuration to protect cardholder data. Separate trusted and untrusted networks. Maintain a security policy for employee-owned devices.
  2. Don’t use vendor defaults for network equipment configurations. Maintain a secure password policy, create a security baseline for systems prior to connecting to the network, and encrypt all non-console admin access for remote access.
  3. Protect cardholder data. Limited storage and retention, don’t store entire card number, mask PAN when displayed, and protect keys used for encryption.
  4. Protect data in transit. Use strong cryptography and secure transport protocols such as IPSEC and HTTPS.
  5. Maintain a vulnerability management program. Use anti-virus software along with a host intrusion detection system and keep them updated!
  6. Develop and maintain secure systems and apps. This requires instituting secure coding standards and best practices. Utilize a change control system and consists of a review and approval process. Software is often the weak link in security!
Recommended Study Material

PCI/DSS PowerPoint notes & PDF version

Learn on the go.
The app designed for the modern cyber security professional.
Get it on Google PlayGet it on the App Store
Practice Labs and Exam Vouchers

Congratulations! You're taking the first step to getting certified. Get some hands on experience with available practice labs OR save some money, support Cybrary, and purchase discounted exam vouchers. Ready to earn your next industry certification? Join cyber security's largest community and start learning today.


Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play

Support Cybrary

Donate Here to Get This Month's Donor Badge

Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?