PCI DSS and the AIC Kits
Analog Informatics Corporation (AIC) kits help an organization that stores, processes, or transmits payment account data control privileged access, log activity, and monitor configuration compliance. This page maps the 12 principal requirements of the Payment Card Industry Data Security Standard (PCI DSS) version 4.0. A qualified security assessor decides the result.

Principal Requirements
| Requirement | What the Kit Does |
|---|---|
| 1. Install and maintain network security controls | Network devices stay with the organization. Jump is the managed privileged path. |
| 2. Apply secure configurations to all system components | Configuration compliance checks enrolled systems against an approved baseline. |
| 3. Protect stored account data | Validated cryptography and the document sharing vault on kit paths. Cardholder databases stay with the organization. |
| 4. Protect cardholder data with strong cryptography during transmission | Validated cryptography on kit paths. |
| 5. Protect all systems and networks from malicious software | Malware protection stays with the organization. |
| 6. Develop and maintain secure systems and software | Current State Compliance records flaws. Patching stays with the organization. |
| 7. Restrict access by business need to know | Privileged Access Management, Privileged User Management, and access review on kit accounts. |
| 8. Identify users and authenticate access | Privileged Identity Management and kit sign-in with another step beyond a password. |
| 9. Restrict physical access to cardholder data | Physical access stays with the organization. |
| 10. Log and monitor all access | Audit, alerts, and continuous monitoring on kit paths. |
| 11. Test security of systems and networks regularly | Penetration testing and scanning stay with the organization. |
| 12. Support information security with organizational policies and programs | The organization owns policy. The Assessment Binder stores it. |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.