💼 8.3.10 If passwords/passphrases are used as the only authentication factor for customer user access to cardholder data, then guidance is provided to customer users.
-
Contextual name: 💼 8.3.10 If passwords/passphrases are used as the only authentication factor for customer user access to cardholder data, then guidance is provided to customer users.
-
ID:
/frameworks/pci-dss-v4.0/08/03/10
-
Located in: 💼 8.3 Strong authentication for users and administrators is established and managed.
Description
Additional requirement for service providers only.
Including:
- Guidance for customers to change their user passwords/passphrases periodically.
- Guidance as to when, and under what circumstances, passwords/passphrases are to be changed.
Similar
- Sections
/frameworks/pci-dss-v3.2.1/08/02/04
/frameworks/pci-dss-v4.0.1/08/03/10
- Internal
- ID:
dec-c-0cda3633
- ID:
Similar Sections (Take Policies From)
Similar Sections (Give Policies To)
Sub Sections
Policies (2)
Policy | Logic Count | Flags |
---|---|---|
📝 AWS Account IAM Password Policy Number of passwords to remember is not set to 24 🟢 | 1 | 🟢 x6 |
📝 AWS IAM User Access Keys are not rotated every 90 days or less 🟢 | 1 | 🟢 x6 |
Internal Rules
Rule | Policies | Flags |
---|---|---|
✉️ dec-x-f7c2faac | 1 |