Assessment and Audit
Build and Maintain a Secure Network and Systems
-
Install and maintain a firewall configuration to protect data.
-
Do not use vendor-supplied defaults for system passwords and other security parameters.
Maintain a Vulnerability Management Program
-
Protect all systems against malware and regularly update anti-virus software or programs.
-
Develop and maintain secure systems and applications.
Implement Strong Access Control Measures
-
Identify and authenticate access to system components.
Regularly Monitor and Test Networks
-
Track and monitor all access to network resources.
-
Regularly test security systems and processes.
Maintain an Information Security Policy
-
Maintain a policy that addresses information security for all personnel.