PCI DSS

The Payment Card Industry Data Security Standard: mandatory requirements for any system that stores, processes or transmits cardholder data. Non-compliance can mean fines or loss of the ability to process card payments.

Authority PCI Security Standards CouncilVersion 4.0.1coverage 200 controlsOfficial documentation →Evidence & exportsID modelOSCAL ↓
4 high174 medium9 low9 OS96% reboot-proof
How to read the references

PCI DSS references are requirement numbers, nested under the standard's 12 top-level requirements, 8.2.1 means Requirement 8 › 2 › 1 (Requirement 8 = identify users and authenticate access to system components). Some references keep the Req- prefix, e.g. Req-2.2.4, and the deepest ones point at a specific testing procedure, e.g. 10.2.5.b.

Pavois maps to PCI DSS 4.0.1, the current version. PCI DSS applies to any system that stores, processes or transmits cardholder data.

200 / 200
RefRuleOSDomainSev.PCI ref
SOCLE-CLD-IAM-001Verify Only Root Has UID 09Accountscritical8.2.1
SOCLE-CLD-IAM-002Verify All Account Password Hashes are Shadowed9Accountscritical8.3.2
SOCLE-CLD-IAM-003Verify Root Has A Primary GID 09Accountshigh8.2.1
SOCLE-CLD-IAM-004Set Account Expiration Following Inactivity8Accounts (login.defs)medium8.2.6
SOCLE-CLD-IAM-005All GIDs referenced in /etc/passwd must be defined in /etc/group9Accountslow8.2.2
SOCLE-CLD-IAM-006Prevent Login to Accounts With Empty Password9Accountscritical2.2.2 · 8.3.1
SOCLE-CLD-IAM-007Ensure all users last password change date is in the past8Accountsmedium8.3.5
SOCLE-RUN-AUD-001Record Events that Modify the System's Discretionary Access Controls - chmod9Audit (auditd)medium10.3.4
SOCLE-RUN-AUD-005Ensure auditd Collects File Deletion Events by User - rename9Audit (auditd)medium10.2.1.7
SOCLE-RUN-AUD-006Make the auditd Configuration Immutable9Audit (auditd)medium10.3.2
SOCLE-RUN-AUD-008Record Attempts to Alter Logon and Logout Events - faillock9Audit (auditd)medium10.2.1.3
SOCLE-RUN-AUD-009Record Events that Modify the System's Mandatory Access Controls9Audit (auditd)medium10.3.4
SOCLE-RUN-AUD-010Ensure auditd Collects Information on Exporting to Media (successful)9Audit (auditd)medium10.2.1.7
SOCLE-RUN-AUD-011Record Events that Modify the System's Network Environment9Audit (auditd)medium10.3.4
SOCLE-RUN-AUD-015Record Attempts to Alter Process and Session Initiation Information9Audit (auditd)medium10.2.1.3
SOCLE-RUN-AUD-018Record Events When Privileged Executables Are Run7Audit (auditd)medium10.2.1.2
SOCLE-RUN-AUD-019Ensure auditd Collects System Administrator Actions8Audit (auditd)medium10.2.1.5
SOCLE-RUN-AUD-020Record attempts to alter time through adjtimex9Audit (auditd)medium10.6.3
SOCLE-RUN-AUD-021Record Attempts to Alter Time Through clock_settime9Audit (auditd)medium10.6.3
SOCLE-RUN-AUD-022Record Unsuccessful Access Attempts to Files - creat9Audit (auditd)medium10.2.1.4
SOCLE-RUN-AUD-023Record Events that Modify User/Group Information - /etc/group9Audit (auditd)medium10.2.1.5
SOCLE-RUN-AUD-026Configure auditd admin_space_left Action on Low Disk Space9Audit (auditd daemon)medium10.5.1
SOCLE-RUN-AUD-032Configure auditd Max Log File Size9Audit (auditd daemon)medium10.5.1
SOCLE-RUN-AUD-033Configure auditd max_log_file_action Upon Reaching Maximum Log Size9Audit (auditd daemon)medium10.5.1
SOCLE-RUN-AUD-034Set type of computer node name logging in audit logs4Audit (auditd daemon)medium10.2.2
SOCLE-RUN-AUD-036Configure auditd space_left Action on Low Disk Space9Audit (auditd daemon)medium10.5.1
SOCLE-RUN-AUD-037Configure auditd space_left on Low Disk Space7Audit (auditd daemon)medium10.5.1
SOCLE-CLD-KRN-001Enable Auditing for Processes Which Start Prior to the Audit Daemon9Kernel command linelow10.7.2
SOCLE-CLD-KRN-002Extend Audit Backlog Limit for the Audit Daemon9Kernel command linelow10.7.2
SOCLE-CLD-KRN-013Ensure SELinux Not Disabled in /etc/default/grub4Kernel command linemedium1.2.6
SOCLE-CLD-GEN-005Disable GNOME3 Automounting9GNOME desktop (dconf)medium3.4.2
SOCLE-CLD-GEN-006Disable GNOME3 Automount Opening9GNOME desktop (dconf)medium3.4.2
SOCLE-CLD-GEN-016Set GNOME3 Screensaver Lock Delay After Activation Period3GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-017Enable GNOME3 Screensaver Idle Activation1GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-018Set GNOME3 Screensaver Inactivity Timeout3GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-019Enable GNOME3 Screensaver Lock After Idle Period9GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-021Implement Blank Screensaver5GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-GEN-024Ensure Users Cannot Change GNOME3 Session Idle Settings8GNOME desktop (dconf)medium8.2.8
SOCLE-CLD-IAM-008Lock Accounts After Failed Password Attempts9Accounts (faillock)medium8.3.4
SOCLE-CLD-IAM-009Set Lockout Time for Failed Password Attempts9Accounts (faillock)medium8.3.4
SOCLE-CLD-GEN-026Ensure that /etc/at.deny does not exist9Cron/at access controlmedium2.2.6
SOCLE-CLD-GEN-028Ensure that /etc/cron.deny does not exist9Cron/at access controlmedium2.2.6
SOCLE-CLD-FSP-001Verify Group Who Owns /etc/at.allow file9File ownershipmedium2.2.6
SOCLE-CLD-FSP-003Verify Group Who Owns Backup group File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-004Verify Group Who Owns Backup gshadow File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-005Verify Group Who Owns Backup passwd File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-006Verify User Who Owns Backup shadow File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-008Verify Group Who Owns /etc/cron.allow file9File ownershipmedium2.2.6
SOCLE-CLD-FSP-009Verify Group Who Owns cron.d9File ownershipmedium2.2.6
SOCLE-CLD-FSP-010Verify Group Who Owns cron.daily9File ownershipmedium2.2.6
SOCLE-CLD-FSP-012Verify Group Who Owns cron.hourly9File ownershipmedium2.2.6
SOCLE-CLD-FSP-013Verify Group Who Owns cron.monthly9File ownershipmedium2.2.6
SOCLE-CLD-FSP-014Verify Group Who Owns cron.weekly9File ownershipmedium2.2.6
SOCLE-CLD-FSP-016Verify Group Who Owns Crontab9File ownershipmedium2.2.6
SOCLE-CLD-FSP-020Verify Group Who Owns group File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-025Verify Group Ownership of System Login Banner for Remote Connections9File ownershipmedium1.2.8
SOCLE-CLD-FSP-027Verify Group Who Owns passwd File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-031Verify Group Who Owns shadow File9File ownershipmedium2.2.6
SOCLE-CLD-FSP-035Verify /boot/grub2/grub.cfg Group Ownership8File ownershipmedium2.2.6
SOCLE-CLD-FSP-040Verify /boot/grub2/user.cfg Group Ownership8File ownershipmedium2.2.6