Laserfiche WebLink
C <br />Part 4. Action Plan for Non -Compliant Requirements <br />Select the appropriate response for "Compliant to PCI DSS Requirements" for each requirement. If you <br />answer "No" to any of the requirements, you may be required to provide the date your Company expects to <br />be compliant with the requirement and a brief description of the actions being taken to meet the requirement. <br />Check with the applicable payment brand(s) before completing Part 4. <br />Compliant to PCI <br />DSS <br />Remediation Date and <br />PCI DSS <br />Description of Requirement <br />Requirements <br />Actions <br />Requirement <br />(Select One) <br />(If "NO" selected for any <br />Requirement) <br />YES <br />NO <br />1 <br />Install and maintain a firewall <br />® <br />❑ <br />configuration to protect cardholder data <br />Do not use vendor -supplied defaults for <br />® <br />❑ <br />2 <br />system passwords and other security <br />parameters <br />3 <br />Protect stored cardholder data <br />® <br />❑ <br />4 <br />Encrypt transmission of cardholder data <br />® <br />❑ <br />across open, public networks <br />Protect all systems against malware and <br />® <br />❑ <br />5 <br />regularly update anti -virus software or <br />programs <br />6 <br />Develop and maintain secure systems <br />® <br />❑ <br />and applications <br />7 <br />Restrict access to cardholder data by <br />® <br />❑ <br />business need to know <br />3 <br />Identify and authenticate access to <br />® <br />❑ <br />system components <br />g <br />Restrict physical access to cardholder <br />data <br />10 <br />Track and monitor all access to network <br />resources and cardholder data <br />11 <br />Regularly test security systems and <br />processes <br />12 <br />Maintain a policy that addresses <br />® <br />❑ <br />information security for all personnel <br />Appendix Al <br />Additional PCI DSS Requirements for <br />® <br />❑ <br />Shared Hosting Providers <br />Additional PCI DSS Requirements for <br />® <br />❑ <br />Appendix A2 <br />Entities using SSL/early TLS for Card - <br />Present POS POI Terminal Connections <br />°'�`•`�a C3: W VISA <br />PCI at ✓vCbfIfitt.*tation of Compliance for Onsite Assessmei24 ice Providers, Rev. 1.0 2/7/2-0262018 <br />© 2006-2018 PC/ Security Standards Council, LLC. All Rights Reserved. Page 12 <br />