
ペイメントカード業界データセキュリティ基準 チェッカー ♪
Protect cardholder data with our kawaii PCI DSS assessment! ✧ Check your compliance with all 12 requirements covering network security, data protection, vulnerability management, and access controls. がんばって!
The Payment Card Industry Data Security Standard protects cardholder data across all organizations that accept, process, store, or transmit credit card information. Version 4.0 is mandatory from March 31, 2025.
ネットワークセキュリティ管理
Do you have firewalls installed and configured to protect cardholder data?
Is there a network diagram showing all connections to cardholder data?
セキュアな設定
Have all vendor-supplied default passwords been changed?
Are system hardening standards documented and applied to all components?
保存データの保護
Is stored cardholder data encrypted using strong cryptography?
Do you have data retention policies limiting storage of cardholder data?
転送中データの保護
Is cardholder data encrypted during transmission over public networks (TLS 1.2+)?
マルウェア対策
Is anti-malware software deployed on all systems commonly affected by malware?
Are anti-malware solutions kept current with automatic updates?
セキュアなシステム開発
Are critical security patches installed within one month of release?
Do you follow secure coding practices (OWASP) for custom applications?
アクセス制限
Is access to cardholder data restricted to personnel with business need?
Is there a role-based access control system with documented roles?
ユーザー認証
Does every user have a unique ID for system access?
Is MFA implemented for all access to the cardholder data environment?
物理アクセス制限
Is physical access to cardholder data areas restricted and monitored?
Are media containing cardholder data physically secured and tracked?
ログ記録と監視
Are all access to cardholder data logged with audit trails?
Are logs reviewed daily and retained for at least one year?
セキュリティテスト
Do you conduct quarterly vulnerability scans by an ASV?
Do you conduct annual penetration testing?
Do you have intrusion detection/prevention systems monitoring the CDE?
情報セキュリティポリシー
Do you have a documented information security policy reviewed annually?
Do all personnel receive security awareness training upon hire and annually?
Our QSA-experienced consultants help merchants and service providers achieve and maintain PCI DSS compliance. From gap assessments to SAQ preparation, we've got you covered!
💌 Get Free Assessment ✧ 無料相談The Payment Card Industry Data Security Standard (PCI DSS) is a global security standard for all organizations that store, process, or transmit cardholder data. Version 4.0, released March 2022, becomes mandatory March 31, 2025.