Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

PCI DSS Requirement 8: Identify & Authenticate User Access

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
1,901
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS Requirement 8 establishes identity and authentication controls intended to protect cardholder data environments by assigning unique user identifiers, verifying users through authentication factors, and maintaining accountability for system actions. Its six sections require documented policies and responsibilities, lifecycle management for user and administrator accounts, strong authentication controls, multi-factor authentication for access to the cardholder data environment and remote connections, safeguards against MFA misuse, and strict management of application and system accounts. Key measures include promptly revoking terminated-user access, disabling inactive accounts within 90 days, re-authenticating idle sessions after 15 minutes, encrypting authentication factors, limiting failed login attempts, enforcing password complexity and reuse restrictions, and preventing shared or interactive system-account use except under approved, traceable exceptions. The material notes alignment with established security practices and NIST identity guidance, while advising readers to consult PCI SSC’s current official requirements. It also promotes Basis Theory’s PCI Level 1-compliant platform as a way for businesses to secure and use card data while reducing the systems they must bring into PCI scope.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.