PCI DSS Requirement 8: Identify & Authenticate User Access
Blog post from Basis Theory
PCI DSS Requirement 8 establishes identity and authentication controls intended to protect cardholder data environments by assigning unique user identifiers, verifying users through authentication factors, and maintaining accountability for system actions. Its six sections require documented policies and responsibilities, lifecycle management for user and administrator accounts, strong authentication controls, multi-factor authentication for access to the cardholder data environment and remote connections, safeguards against MFA misuse, and strict management of application and system accounts. Key measures include promptly revoking terminated-user access, disabling inactive accounts within 90 days, re-authenticating idle sessions after 15 minutes, encrypting authentication factors, limiting failed login attempts, enforcing password complexity and reuse restrictions, and preventing shared or interactive system-account use except under approved, traceable exceptions. The material notes alignment with established security practices and NIST identity guidance, while advising readers to consult PCI SSC’s current official requirements. It also promotes Basis Theory’s PCI Level 1-compliant platform as a way for businesses to secure and use card data while reducing the systems they must bring into PCI scope.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.