What does PA-DSS Cover?
PA-DSS (Payment Application Data Security Standards) are the standards that Triple E is required to follow.
1. Use Windows firewall to protect cardholder data; it drops all incoming traffic not corresponding to a host request.
2. Removed vendor-supplied defaults for passwords and security parameters before system use.
3. Payment card authentication data is not stored, except when an employee physically possesses a customer payment card. The full account number is never revealed.
4. Supported anti-virus software use and updates with specific settings for OneTouch® Suite servers.
5. Assign user access rights and permissions based on group accounts and merchant privileges.
6. Windows authentication; unique ID and password required for user access to OneTouch® Suite.
7. User activity event logging, including logins, logoffs, security rights changes, and database object accesses.