Entity has a documented Password Policy and makes it available to all staff members on the company employee portal
Entity ensures all sessions accessing the in-scope environment are configured to timeout within 15 minutes of inactivity
Entity identifies vulnerabilities in the network through regular network scanning exercises conducted by an Approved Scanning Vendors
Entity ensures that card holder data is not used in testing or development environments
Entity identifies vulnerabilities in the network components like servers that are used to host the in-scope application through the execution of regular vulnerability scans
Entity ensures all staff members receive training to understand their responsibilities regarding processing of sensitive cardholder information