Requirement 7: Restrict Access to System Components and Cardholder Data by Business Need to Know
PCI DSS v4.0.1 Requirement 7: least privilege, role-based access to cardholder data, and the access review cycle assessors check first.
Requirement 7 is about who may see cardholder data and why. It pairs with Requirement 8, which proves the person using an account is who they claim to be.
PCI DSS v4.0.1 breaks this requirement into 3 sections containing 12 individual controls.
What this requirement is actually asking
Access is granted on business need to know and least privilege, denied by default. The default-deny position (7.2.5) is what most legacy systems fail, because permissions accumulated over years and nobody ever removed any.
v4.0.1 sharpened the review cycle: access rights are reviewed at least every six months (7.2.4), and the review must confirm the access is still appropriate. A signature on an unchanged list is not evidence of a review.
Does it apply to you?
All system components in scope, and all accounts including application and system accounts (7.2.5).
The controls
Requirement 7 contains 12 controls across 3 sections. Each links to its own page with the requirement in full and the testing procedures an assessor uses to verify it.
7.1: Governance for restricting access by business need to know
| Control | What it requires | Guidance |
|---|---|---|
| 7.1.1 | All security policies and operational procedures that are identified in Requirement 7… | Yes |
| 7.1.2 | Roles and responsibilities for performing activities in Requirement 7 are documented, assigned… | Yes |
7.2: Access is defined, assigned by role, and approved
| Control | What it requires | Guidance |
|---|---|---|
| 7.2.1 | An access control model is defined and includes granting access… | Yes |
| 7.2.2 | Access is assigned to users, including privileged users, based… | Yes |
| 7.2.3 | Required privileges are approved by authorized personnel | Yes |
| 7.2.4 | All user accounts and related access privileges, including third-party/vendor accounts… | Yes |
| 7.2.5 | All application and system accounts and related access privileges are assigned and managed… | Yes |
| 7.2.5.1 | All access by application and system accounts and related access privileges are reviewed… | Yes |
| 7.2.6 | All user access to query repositories of stored cardholder data is restricted… | Yes |
7.3: Access control systems enforce it, set to deny-all by default
| Control | What it requires | Guidance |
|---|---|---|
| 7.3.1 | An access control system(s) is in place that restricts access based on a user’s need to know… | Yes |
| 7.3.2 | The access control system(s) is configured to enforce permissions assigned to individuals… | Yes |
| 7.3.3 | The access control system(s) is set to “deny all” by default | Yes |
Evidence your assessor will ask for
- A role definition matrix mapping job function to the privileges granted
- Signed approval records for privilege assignment
- Six-monthly access review output showing what was removed, not only what was confirmed
Where this commonly fails
- Access reviews that confirm every account every time. A review that never removes anything reads as a rubber stamp
- Application and system accounts excluded from review because they are not people
- Privilege creep from role changes, where the old access was never revoked
Official source
This page is original commentary. It cites requirement identifiers and the official requirement title, and does not reproduce the text of the standard. For the authoritative wording, including each testing procedure and the customized approach objective, download PCI DSS v4.0.1 (June 2024) from the PCI Security Standards Council document library.
PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site.