The Payment Card Industry Data Security Standard (PCI DSS) specifies best practices and security controls needed to keep credit card data safe and secure during transit, processing, and storage. Mainly, organizations must:
- Build and maintain a secure network
- Protect cardholder data
- Maintain a vulnerability management program
- Implement strong security measures
- Test and monitor networks on a regular basis
- Maintain an information security policy
Recently, our Wazuh Cloud platform has been validated as PCI DSS Level 1 Service Provider compliant. The validation was provided by a QSA (Qualified Security Assessor) firm qualified by the PCI Security Standards Council to validate an entity’s adherence to PCI DSS.
The Attestation of Compliance (AoC) serves as evidence for our customers that Wazuh Cloud is compliant with the PCI DSS v3.2.1 security standard. This AoC is effective as of November 3, 2019.
Quick overview to PCI DSS
Launched by five global payment brands (American Express, Discover, MasterCard, Visa, and JCB), Payment Card Industry Data Security Standard (PCI DSS) is a set of standards that require merchants and service providers that store, process, or transmit customer payment card data to adhere to strict information security controls and processes. The standard includes 12 requirements:
- Install and maintain a firewall configuration to protect cardholder data
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Protect stored cardholder data
- Encrypt transmission of cardholder data across open, public networks
- Use and regularly update anti-virus software or programs
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need to know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security for all personnel
Read more about the requirements in PCI Security Standards.
Benefits of being PCI DSS compliance
The top benefits that you can expect when an organization achieves PCI DSS compliance are:
- Reducing security risks: PCI DSS is a way to improve the security, preventing attacks and protecting customer data.
- Adhering to security standards: PCI DSS is a set of standards accepted globally. The requirements are clearly defined and auditable.
- Trusted service: Our customers can leverage their deployment to our cloud infrastructure knowing that we are compliant with all the PCI requirements. Being compliance is not only tick boxes but rather a way to improve security which is for the benefit of the business and its customers.
In summary, PCI DSS is often considered as a good indicator of the ability of an organization to secure any type of sensitive data, even when the service is not processing, storing or transmitting credit card data.
Our main priority in Wazuh is keeping our customers safe. Extensive resources are dedicated to this purpose and PCI DSS is just the beginning. We are in the process of new security certifications like SOC2. Reach out to us for more information.