© The Author(s), under exclusive license to APress Media, LLC, part of Springer Nature 2023
A. B. Cooper Jr. et al.The Definitive Guide to PCI DSS Version 4https://doi.org/10.1007/978-1-4842-9288-4_8

8. Restrict Access to System Components and Cardholder Data by Business Need to Know

Arthur B. Cooper Jr.1  , Jeff Hall2, David Mundhenk3 and Ben Rothke4
(1)
Colorado Springs, CO, USA
(2)
Minneapolis, MN, USA
(3)
Austin, TX, USA
(4)
Clifton, NJ, USA
 

Overview

This requirement isn’t exciting when you first look at it. The title is long, and it seems to be something that common sense would dictate anyway, right? I mean, why wouldn’t you restrict access from everyone with “no need to know”? Unfortunately, as we all know, common sense isn’t very common, and any QSA ...

Get The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.