PCI DSS v4.0

    All production database[s] that store customer data are encrypted at rest.
    Entity provides guidance on decomissioning of information assets that contain classified information in the Media disposal policy.
    Entity ensures that endpoints with access to critical servers or data are configured to auto-screen-lock after 15 minutes of inactivity
    Entity ensures that security patches to the operating systems are applied to endpoints with access to critical servers or data in a timely manner
    Where applicable, Entity ensures that endpoints with access to critical servers or data must be encrypted to protect from unauthorised access
    Where applicable, Entity ensures that endpoints with access to critical servers or data must be protected by malware-protection software