Research Article

Towards Secure IoT-Based Payments by Extension of Payment Card Industry Data Security Standard (PCI DSS)

Table 1

Control objectives and security requirements of PCI DSS [7].

Control objectivesPCI DSS security requirementsPA DSS security requirements

CO1: build and maintain a secure networkR1: install and maintain a firewall configuration to protect cardholder dataRA1: do not retain full track data, card verification code, or value
R2: do not use vendor-supplied defaults for system passwords and other security parameterRA2: protect stored cardholder data
CO2: protect cardholder dataR3: protect stored cardholder dataRA3: provide secure authentication features
R4: encrypt transmission of cardholder data across open, public networksRA4: log payment application activity
CO3: maintain a vulnerability management programR5: protect all systems against malware and regularly update antivirus software or programsRA5: develop secure payment applications
R6: develop and maintain secure systems and applicationsRA6: protect wireless transmissions
CO4: implement strong access control measuresR7: restrict access to cardholder data by business need to knowRA7: test payment applications to address vulnerabilities and maintain payment application updates
R8: identify and authenticate access to system componentsRA8: facilitate secure network implementation
R9: restrict physical access to cardholder dataRA9: cardholder data must never be stored on a server connected to the Internet
CO5: regularly monitor and test networksR10: track and monitor all access to network resources and cardholder dataRA10: facilitate secure remote access to payment application
R11: regularly test security systems and processesRA11: encrypt sensitive traffic over public networks
CO6: maintain an information security policyR12: maintain a policy that addresses information security for all personnelRA12: encrypt all nonconsole administrative access
RA13: maintain a PA-DSS implementation guide for customers, resellers, and integrators
RA14: assign PA-DSS responsibilities for personnel and maintain training programs for personnel, customers, resellers, and integrators