Requirement 8 · Identify users and authenticate access to system components

8.2 User identification and accounts are managed

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL8.2 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Assign unique IDs, no shared accounts, and remove access promptly on departure.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 8.2, in plain English.

8.2.1Every user gets a unique ID before being allowed access to system components or cardholder data.
8.2.2Shared, group, or generic IDs are used only by exception, justified, approved, time-limited, and traceable to a person.
8.2.3Service providers with remote access to customer premises use a different authentication factor per customer site.
8.2.4Adding, deleting, and changing IDs and authentication factors is properly approved and limited to approved privileges.
8.2.5Access for terminated users is revoked immediately.
8.2.6Inactive user accounts are removed or disabled within 90 days.
8.2.7Third-party remote-access accounts are enabled only when needed, disabled when not, and monitored.
8.2.8After 15 minutes of idle time, a user must re-authenticate to resume the session.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 8, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.