Entity makes all policies and procedures available to all staff members via the company employee portal
Entity stores encryption keys used to secure card holder data in a secure location
Entity ensures that only the permissible card data is stored in a manner as per the PCI DSS requirements
Entity has a documented Cardholder Data Management Policy and makes it available to all staff members on the company employee portal
Entity ensures that servers used to process in-scope data are hardened
Entity requires that all endpoints with access to the environment housing the in-scope data are protected by a Firewall