PCI Requirement 8, what about Administrator accounts? standard
I had a customer ask me if they had to make the Administrator account/password comply with Requirement 8 of the PCI Standards. Requirement 8 deals with assigning a unique ID to each person with computer access to those systems dealing with cardholder data. Specifically, no generic or shared accounts should be used–especially those that are administrators! The answer is YES, they must comply with the requirements. What does that mean from an operational standpoint? We see customers attack this from various angles. For those corporate systems, they are typically just disabling the Administrator account, and putting special alerting in place to see if it is ever used (as in something bad is happening, go deploy the calvary). In the case ...
Continue Reading