Skip to main content

๐Ÿ’ผ 2 Do not use vendor-supplied defaults for system passwords and other security parameters.

  • Contextual name: ๐Ÿ’ผ 2 Do not use vendor-supplied defaults for system passwords and other security parameters.
  • ID: /frameworks/pci-dss-v3.2.1/02
  • Located in: ๐Ÿ’ผ PCI DSS v3.2.1

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-b-509216cb

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 2.1 Always change vendor-supplied defaults and remove or disable unnecessary default accounts before installing a system on the network.12
ย ย ย ย ๐Ÿ’ผ 2.1.1 For wireless environments connected to the cardholder data environment or transmitting cardholder data, change ALL wireless vendor defaults at installation, including but not limited to default wireless encryption keys, passwords, and SNMP community strings.
๐Ÿ’ผ 2.2 Develop configuration standards for all system components. Assure that these standards address all known security vulnerabilities and are consistent with industry-accepted system hardening standards.52
ย ย ย ย ๐Ÿ’ผ 2.2.1 Implement only one primary function per server to prevent functions that require different security levels from co-existing on the same server.
ย ย ย ย ๐Ÿ’ผ 2.2.2 Enable only necessary services, protocols, daemons, etc., as required for the function of the system.
ย ย ย ย ๐Ÿ’ผ 2.2.3 Implement additional security features for any required services, protocols, or daemons that are considered to be insecure.33
ย ย ย ย ๐Ÿ’ผ 2.2.4 Configure system security parameters to prevent misuse.1
ย ย ย ย ๐Ÿ’ผ 2.2.5 Remove all unnecessary functionality, such as scripts, drivers, features, subsystems, file systems, and unnecessary web servers.
๐Ÿ’ผ 2.3 Encrypt all non-console administrative access using strong cryptography.34
๐Ÿ’ผ 2.4 Maintain an inventory of system components that are in scope for PCI DSS.
๐Ÿ’ผ 2.5 Ensure that security policies and operational procedures for managing vendor defaults and other security parameters are documented, in use, and known to all affected parties.
๐Ÿ’ผ 2.6 Shared hosting providers must protect each entity's hosted environment and cardholder data.