•
Understand and document how your business transacts, collects, processes, stores and interacts with payment card account data. This is also referred to as scoping.
•
If you do not need payment card account data, do not store it.
•
Limit access to payment card account data and systems on a need-to-know basis.
•
Limit the number of people, processes and technologies needed to complete payment card acceptance functions.
•
Use and maintain strong passwords when accessing systems.
•
Complete the applicable PCI DSS validation documents to demonstrate your business’ compliance.
•
Physically inspect and secure payment terminals from unauthorized alterations or tampering.
•
Ensure software is up to date with latest patches and versions.
•
Work with PCI DSS compliant Third-Party Service Providers, Approved Scanning Vendors and Qualified Security Assessors.
•
Continuously educate employees on security best practices