PCI 2:
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
- Hackers (external and internal to a company) often use vendor default passwords and other vendor default settings to compromise systems. These passwords and settings are well known in hacker communities and easily determined via public information.
- PCI-2.1 Always change the vendor-supplied defaults before you install a system on the network (e.g., passwords, SNMP community strings, and elimination of unnecessary accounts).
- PCI-2.2 Develop configuration standards for all system components. Make sure these standards address all known security vulnerabilities and industry best practices.
--Mdpeters 08:33, 26 June 2006 (EDT)