What Are the 13 Requirements for PCI DSS 3.2.1 2018 Compliance?
Navigating PCI DSS: Understanding the Intent of the Requirements, PCI DSS v3.2.1
Build and Maintain a Secure Network
- Requirement 1: Install and maintain a firewall configuration to protect cardholder data
- Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
- Requirement 3: Protect stored cardholder data
- Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
- Requirement 5: Use and regularly update anti-virus software
- Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
- Requirement 7: Restrict access to cardholder data by business need-to-know
- Requirement 8: Assign a unique ID to each person with computer access
- Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
- Requirement 10: Track and monitor all access to network resources and cardholder data
- Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
- Requirement 12: Maintain a policy that addresses information security
Appendix A: Additional PCI DSS Requirements for Shared Hosting Providers
There are Six Steps to Achieving PCI Compliance - Facilitated Compliance Management Approach, along with partner programs Security Compass SD Elements and a range of qualified QSA (Qualified Security Assessors), are ready to step you through every single one.
- Build and Maintain a Secure Network
- Protect Cardholder Data
- Implement Strong Access Control Measures
- Regularly Monitor and Test Networks
- Maintain a Vulnerability Management Program
- Maintain an Information Security Policy
The Facilitated Compliance Management approach uses the Policy Mapping, Control Self-Assessment, CMDB, and RunBook methodologies. For a Robust GRC, we suggest Archer eGRC, Cavirin ARAP, or Metric Stream plus a variety of API integrated network management and monitoring tools.
Customers often worry that their ISMS program, their FedRamp program, or other areas of their regulatory requirements are creating redundant conflicting operations tasks. We worry too. That's why we carefully maintain mapping over all of these standards.

Security Programs Overview
There are Six Steps to Achieving PCI Compliance, seven if you add Appendix for Hosted Environments
- Build and Maintain a Secure Network
- Protect Cardholder Data
- Implement Strong Access Control Measures
- Regularly Monitor and Test Networks
- Maintain a Vulnerability Management Program
- Maintain an Information Security Policy
Governance
Extend organizational practices pertaining to the policies, procedures, and standards used for application development and service provisioning in the cloud, as well as the design, implementation, testing, and monitoring of deployed or engaged services. Put in place audit mechanisms and tools to ensure organizational practices are followed throughout the system lifecycle.
Compliance
Understand the various types of laws and regulations that impose security and privacy obligations on the organization and potentially impact cloud computing initiatives, particularly those involving data location, privacy and security controls, and electronic discovery requirements. Review and assess the cloud provider’s offerings with respect to the organizational requirements to be met and ensure that the contract terms adequately meet the requirements.
Trust
Incorporate mechanisms into the contract that allow visibility into the security and privacy controls and processes employed by the cloud provider, and their performance over time. Institute a risk management program that is flexible enough to adapt to the continuously evolving and shifting risk landscape.
Architecture
Understand the underlying technologies the cloud provider uses to provision services, including the implications of the technical controls involved on the security and privacy of the system, with respect to the full lifecycle of the system and for all system components.
Identity and Access Management
Ensure that adequate safeguards are in place to secure authentication, authorization, and other identity and access management functions.
Software Isolation
Understand virtualization and other software isolation techniques that the cloud provider employs, and assess the risks involved. Data Protection Evaluate the suitability of the cloud provider’s data management solutions for the organizational data concerned.
Availability
Ensure that during an intermediate or prolonged disruption or a serious disaster, critical operations can be immediately resumed and that all operations can be eventually reinstituted in a timely and organized manner.
Incident Response
Understand and negotiate the contract provisions and procedures for incident response required by the organization.
Mapping and Tagging
EnterpriseGRC Solutions reviews the organic policies of each organization and maps them to all of the clients' compliance milestones. We've been mapping PCI and ISO since their inception. When our clients prepare for any single compliance event, usually starting with their ISMS and array of certs such as Cloud, Privacy, and Processing, we also provide readiness measures to other assessments such as PCI DSS, SOC 2, FedRAMP, STAR CCM, and HIPAA.




Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics