8.6 PCI DSS (v3.2.1)

Compliance Standard

Compliance Version

Control ID




Requirement 8: Assign a unique ID to each person with computer access


Where other authentication mechanisms are used (for example, physical or logical security tokens, smart cards, certificates, etc.), use of these mechanisms must be assigned as follows:

• Authentication mechanisms must be assigned to an individual account and not shared among multiple accounts.
• Physical and/or logical controls must be in place to ensure only the intended account can use that mechanism to gain access.

