Building and maintaining Requirement 1 – Install and maintain firewall configurations that
secure networks and protect payment card data.
systems Requirement 2 – Avoid vendor defaults for passwords and other
system security controls.
Protecting cardholder data Requirement 3 – Implement protection measures for cardholder
data in storage.
Requirement 4 – Encrypt data in transit over open networks like
the Internet.
Implementing a vulnerability Requirement 5 – Implement antivirus and anti-malware software
management strategy across all systems and ensure regular updates.
Requirement 6 – Build and maintain secure applications and
systems.
Enforcing strong access Requirement 7 – Limit access to cardholder data on a need-to-
control know basis.
Requirement 8 – Use identification and authentication to control
access to all system components.
Requirement 9 – Limit physical access to stored data.
Monitoring and testing the Requirement 10 – Regularly monitor and track all access to
network cardholder data and network resources.
Requirement 11 – Regularly evaluate security processes and
systems.
Maintaining an information Requirement 12 – Maintain a policy that covers data
security policy security for all persons
The PCI DSS consists of 12 requirements. The following practices should help you
ensure PCI compliance in Azure.