Sectona helps you achieve compliance with this standard by delivering and ensuring administrative access to your cardholder data environment is controlled, secured, and monitored. It further helps add value by providing rich analytics to improve visibility around user access to your cardholder data environment. Enterprises must be compliant with the PCI-DSS v3.2.1 around clauses of privileged access as highlighted below:
Do not use vendor-supplied defaults for system passwords and other security parameters
2.1, 2.3, 2.6
Restrict access to cardholder data by business need to know
7.1, 7.2, 7.3
Identify and authenticate access to system components
8.1, 8.2, 8.3, 8.5, 8.8
Track and monitor all access to network resources and cardholder data
10.1, 10.2, 10.3, 10.5, 10.7, 10.9
Explore How Sectona Helps You achieve Compliance with PCI DSS
Manage and Inventorize privileged accounts across infrastructure. Leverage strong password change capabilities from discovery, onboarding to rotation for all vendor supplied default accounts.
Configure access policy definitions based on user roles & functions. Define access to critical data and enforce restrictions on a need-to-know, need-to-access basis with strong workflow based access.
Leverage deep integration with Active Directory for faster provisioning and de-provisioning of access. Control third-party vendor access by defining hybrid access mechanisms. Configure customizable MFA options to enforce second level of authentication for users.