Five Steps to PCI DSS Compliance

PCI DSS
Verfasst von
Darryl K. Taft
Darryl K. Taft
Published: Nov 20, 2014
Updated: Feb 2, 2021
2 minute read
eWeek Inhalte und Produktempfehlungen sind redaktionell unabhängig. Wir können Geld verdienen, wenn Sie auf Links zu unseren Partnern klicken. Mehr erfahren


Five Steps to PCI DSS Compliance

1 - Five Steps to PCI DSS Compliance

by Darryl K. Taft


Overcome the Culture of Undocumented Changes

2 - Overcome the Culture of Undocumented Changes

Tracking changes is a tedious process, but it’s essential for avoiding a data breach that could ruin the financial quarter for an organization. Documentation is important because an organization can’t protect what it doesn’t know is there. Without complete and up-to-date documentation, an organization has no way of knowing where cardholder data sits within the depths of its infrastructure and thus what layers of protection are needed where.


Shrink the Cardholder Data Environment

3 - Shrink the Cardholder Data Environment

Most organizations have no clear idea how far their cardholder data environment extends, which is important because any device not touching cardholder data does not have to meet the long list of PCI DSS requirements. Thoroughly knowing your cardholder data environment can save an organization time and money.


Advertisement

Make Network Segmentation Rock-Solid

4 - Make Network Segmentation Rock-Solid

If any cardholder data can leak from the “safe” environment or another segment can touch that data, your organization is out of compliance and at risk of a breach. Remember that firewalls are required on every port from the external Internet to the internal environment, so no traffic is unchecked. ACLs must also be secured, so no traffic goes through a nonsecured protocol, and unneeded services must be turned off so they can’t be used by attackers.


Know What to Ask a Cloud Service Provider

5 - Know What to Ask a Cloud Service Provider

Not all “compliant” cloud providers are created equal—make sure to ask the right questions, including “How do you segment your network to segregate traffic from different customers?” and “What security certifications do you have and what audits have your cloud platforms undergone?”


Assure the Needed Skills Are In-House

6 - Assure the Needed Skills Are In-House

Those involved with creating or supporting PCI-compliant systems should have basic training in performing daily tasks with a “PCI-centric” mindset. Ask new hire candidates how they would go about configuring firewalls to meet the PCI network administration requirements. To ensure the effectiveness of your compliance program, only hire those candidates who can provide you with a solid answer.

Darryl K. Taft

Darryl K. Taft covers the development tools and developer-related issues beat from his office in Baltimore. He has more than 10 years of experience in the business and is always looking for the next scoop. Taft is a member of the Association for Computing Machinery (ACM) and was named 'one of the most active middleware reporters in the world' by The Middleware Co. He also has his own card in the 'Who's Who in Enterprise Java' deck.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Eigentum von TechnologyAdvice. © 2026 TechnologyAdvice. Alle Rechte vorbehalten

Werbetreibenden-Offenlegung: Einige der auf dieser Website erscheinenden Produkte stammen von Unternehmen, von denen TechnologyAdvice eine Vergütung erhält. Diese Vergütung kann beeinflussen, wie und wo Produkte auf dieser Website erscheinen, einschließlich beispielsweise der Reihenfolge, in der sie erscheinen. TechnologyAdvice schließt nicht alle Unternehmen oder alle auf dem Marktplatz verfügbaren Produkttypen ein.