2.2 System components are configured and managed securely
How to meet it
Apply hardening baselines, change all vendor defaults, and remove unnecessary services/accounts.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 2.2, in plain English.
2.2.1Configuration standards cover all system components, fix known vulnerabilities, align with hardening guidance, and are applied before a component goes into production.
2.2.2Vendor default accounts are handled by changing the default password if kept, or removing/disabling the account if unused.
2.2.3Primary functions needing different security levels are kept apart, isolated, or all secured to the highest level required.
2.2.4Only necessary services, protocols, daemons, and functions are enabled; anything unnecessary is removed or disabled.
2.2.5When insecure services or protocols are present, a business reason is documented and extra security features are applied to reduce risk.
2.2.6System security parameters are set to prevent misuse.
2.2.7All non-console administrative access is encrypted with strong cryptography.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.
Open the control-to-policy map← 2.1 Processes and mechanisms are defined and understood2.3 Wireless environments are configured and managed securely →
Back to Requirement 2, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.