PCI (Payment Card Industry Security Standard)_Req 8.6

PCI (Payment Card Industry Security Standard)

Identify and authenticate access to system components

Req 8.6

8.6 Where other authentication mechanisms are used (for example physical or logical security tokens smart cards certificates etc.) use of these mechanisms must be assigned as follows: – Authentication mechanisms must be assigned to an individual account and not shared among multiple accounts. – Physical and/or logical controls must be in place to ensure only the intended account can use that mechanism to gain access.

If user authentication mechanisms such as tokens smart cards and certificates can be used by multiple accounts it may be impossible to identify the individual using the authentication mechanism. Having physical and/or logical controls (for example a PIN biometric data or a password) to uniquely identify the user of the account will prevent unauthorized users from gaining access through use of a shared authentication mechanism.

 

Click here to Start your FREE trial today!

Explainer video

 

What is a Cybersecurity Compliance Framework?

You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.

With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.

The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:

Click here to Start your FREE trial today!

Explainer video