Under active development Content is continuously updated and improved

2.2.2Vendor default accounts are managed as follows: If the vendor default account(s) will be used, the default password is changed per Requirement 8.

>Requirement Description

Vendor default accounts are managed as follows: If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. If the vendor default account(s) will not be used, the account is removed or disabled. Applicability Notes This applies to ALL vendor default accounts and passwords, including, but not limited to, those used by operating systems, software that provides security services, application and system accounts, point-of-sale (POS) terminals, payment applications, and Simple Network Management Protocol (SNMP) defaults. This requirement also applies where a system component is not installed within an entity’s environment, for example, software and applications that are part of the CDE and are accessed via a cloud subscription service.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.