View Single Post
Old 05-08-2013, 01:12 PM  
PR_Phil
Confirmed User
 
Industry Role:
Join Date: Apr 2003
Location: knee deep in dirty diapers
Posts: 1,960
https://www.pcisecuritystandards.org...pci_dss_v2.pdf

I have nothing to say about Paxum here, but that is a link to PCI DDS requirements for Data Security.

rule 8.5.9 - Change user passwords at least every 90 days.

rule 8.5.10 - Require a minimum password length of at least seven characters.

rule 8.5.11 - Use passwords containing both numeric and alphabetic characters.

rule 8.5.12 - Do not allow an individual to submit a new password that is the same as any of the last four passwords he or she has used.

rule 8.5.13 - 3 Limit repeated access attempts by locking out the user ID after not more than six attempts.

if you go to that link and scroll to page 49, you can view a complete list of the rules regarding user passwords, I would expect a company that controls peoples money to follow PCI regulations.
__________________
PR_Phil is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote