Implement strong access control measures

Requirement 7: Restrict access to system components and cardholder data by business need to know

People should only access the data and systems their job requires, on a least-privilege basis.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 7 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Define roles and map data access to each; default to deny.
  • Keep approval records for every access grant.

Evidence to keep

  • Access control policy
  • Role definitions
  • Access-grant approvals

Example

Access is role-based in the IdP, default-deny, and each grant has a documented approval ticket.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map