PCI DSS · Domain 4
Access Control Measures
About 15% of the exam
Requirement 7, need to know
- Principle
- deny all, allow by exception
- Basis
- job function and least privilege
- Approval
- documented by authorized parties
- Access control system
- enforces the defined policy
- User review
- at least every six months
- Application accounts
- reviewed and managed as well
- Roles
- privileges defined per role
Version 4.0 added periodic review of application and system accounts, so service accounts can no longer drift unwatched
Requirement 8, identify and authenticate
- Every user gets a unique identifier
- Shared and generic accounts prohibited
- Group accounts only under strict controls
- Passwords at least twelve characters
- Mixed numeric and alphabetic characters
- Changed quarterly or monitored dynamically instead
- Idle sessions end after fifteen minutes
- Access revoked immediately upon termination
The password minimum rose to twelve characters in version 4.0, with dynamic posture analysis as the alternative to rotation
Multi factor authentication
- Required for all remote network access
- Required for administrative access to the CDE
- Required for all access into the CDE
- At least two different factor types
- All factors must succeed before access
- Not susceptible to replay attacks
- No bypass without documented exception
Requirement 9, physical access
- Entry controls for sensitive areas
- Visitors identified, escorted and logged
- Badges distinguish staff from visitors
- Physical access revoked when people leave
- Media inventoried and stored securely
- Media destroyed when no longer needed
- Payment terminals inspected for tampering
Access control failures
- Shared administrator credentials between engineers
- Leaver accounts still active weeks later
- Access granted by ticket without approval
- Vendor accounts enabled between visits
- Session timeouts disabled for convenience
- Review completed without removing anything
Third party access
- Unique credentials per customer environment
- Enabled only when needed, then disabled
- Activity monitored while the session runs
- Access agreements signed in advance
- Remote sessions use multi factor authentication
Authentication factors
- Something you know
- password or passphrase
- Something you have
- token, smart card or device
- Something you are
- fingerprint or another biometric
- Two of one kind
- does not count as multi factor
- Passkeys
- can satisfy strong authentication
- Certificates
- bound to a device or user
Privileged accounts
- Granted only where duties require it
- All actions logged and reviewed
- Separate from the daily use account
- Session recording for sensitive work
- Just in time elevation where possible
Mobile and endpoint access
- Device encryption before CDE access
- Remote wipe capability available
- Screen lock and strong authentication
- Copying PAN to the device restricted
- Managed devices only for administration
Joiner, mover, leaver
- Request raised
- Business justification recorded
- Approval by authorized party
- Access provisioned to the role
- Role change triggers review
- Termination triggers revocation
- Periodic review confirms
- Movers accumulate access unless reviewed
- Revocation covers physical and logical
- Badges, tokens and devices returned
- Evidence of each step retained
Evidence assessors ask for
- Access control policy and role definitions
- Approval records for a sampled user
- Six monthly access review outputs
- Termination records with revocation timestamps
- Multi factor configuration settings shown live
- Visitor log covering the required period
- Media inventory and destruction records
Physical details examiners like
- Visitor logs retained for three months
- Badge returned or deactivated on departure
- Media classified before it is moved
- Secure courier tracked for sensitive media
- Terminal serial numbers checked against a list
- Staff trained to report tampering
- Consoles in public areas protected
Rapid recall: numbers
- Password length
- at least twelve characters
- Password change
- every ninety days
- Idle timeout
- fifteen minutes maximum
- Access review
- every six months
- Failed attempts
- locked after ten tries
- Lockout duration
- thirty minutes or verified reset
- Visitor logs
- kept at least three months
Requirements 7, 8 and 9 in a line
- Requirement 7
- who may see cardholder data
- Requirement 8
- prove who is asking
- Requirement 9
- who may physically reach it
- Common thread
- least privilege, uniquely identified
- Failure mode
- access that outlives the need
Reference strip: authorize, authenticate, elevate, enter, review
Authorize
- Deny by default
- Job function drives privilege
- Approval documented per grant
Authenticate
- Unique identifier per person
- Twelve character minimum passwords
- Multi factor into the CDE
Elevate
- Separate privileged accounts
- Actions logged and reviewed
- Vendor access enabled on demand
Enter
- Visitors escorted and logged
- Media stored and destroyed securely
- Terminals inspected for tampering
Review
- Users every six months
- Application accounts included
- Leavers revoked immediately
Quick exam traps
- Trap: Two passwords count as multi factor authentication
- Trap: Multi factor is only needed for remote access from outside
- Trap: A shared administrator account is acceptable if usage is logged
- Trap: Access reviews satisfy the requirement even when nothing is ever removed
- Trap: Physical access has nothing to do with cardholder data protection
- Trap: Vendor accounts may stay enabled between support visits
- Trap: Application and service accounts fall outside the access review
cybercertprep.com · original revision sheet written from the public body of knowledge