PCI DSS and the AIC Kits

Analog Informatics Corporation (AIC) kits help an organization that stores, processes, or transmits payment account data control privileged access, log activity, and monitor configuration compliance. This page maps the 12 principal requirements of the Payment Card Industry Data Security Standard (PCI DSS) version 4.0. A qualified security assessor decides the result.

A payment terminal and a blank payment card protected by an isolated data boundary
PCI DSS and the AIC Kits

What Availability Means

Principal Requirements

RequirementWhat the Kit Does
1. Install and maintain network security controlsNetwork devices stay with the organization. Jump is the managed privileged path.
2. Apply secure configurations to all system componentsConfiguration compliance checks enrolled systems against an approved baseline.
3. Protect stored account dataValidated cryptography and the document sharing vault on kit paths. Cardholder databases stay with the organization.
4. Protect cardholder data with strong cryptography during transmissionValidated cryptography on kit paths.
5. Protect all systems and networks from malicious softwareMalware protection stays with the organization.
6. Develop and maintain secure systems and softwareCurrent State Compliance records flaws. Patching stays with the organization.
7. Restrict access by business need to knowPrivileged Access Management, Privileged User Management, and access review on kit accounts.
8. Identify users and authenticate accessPrivileged Identity Management and kit sign-in with another step beyond a password.
9. Restrict physical access to cardholder dataPhysical access stays with the organization.
10. Log and monitor all accessAudit, alerts, and continuous monitoring on kit paths.
11. Test security of systems and networks regularlyPenetration testing and scanning stay with the organization.
12. Support information security with organizational policies and programsThe organization owns policy. The Assessment Binder stores it.

Screenshots

Privileged credentials are vaulted and rotated. Operators never see the secret.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.