Safe Commerce Requirements
- Requirements of the Safe Commerce certification:
- Systems must be on a secure network.
- If Cardholder data is stored it must be behind a suitably strong firewall, configured to protect the data.
- Default passwords must not be used on the system.
- Cardholder data must be encrypted during transmission.
- A Vulnerability Management Program must be implemented.
- Antivirus software must be used.
- Access to cardholder data by business need-to-know
- All persons with access to the data must have unique authentication details
- Physical access to cardholder data must be restricted.
- Track and monitor all access to network resources and cardholder data
- Maintain an information security policy
- Maintain a policy that addresses information security