Authentication Credential
PCIComplianceHubLast updated
An account identifier together with the authentication factor or factors used to prove it: a user ID plus its password, a badge plus its PIN, a certificate bound to a device. The pair is what a system checks; either half alone proves nothing.
Applies to. Every user, device and process that authenticates to an in-scope system component.
Example. A shared login the whole night shift knows is a credential that identifies a group, not a person. 8.2.2 allows shared credentials only when necessary, on an exception basis, with management approval and with every use attributable to an individual.
Limits. PCI DSS's rules for credentials are mostly rules about the factor: minimum length and complexity for passwords (8.3.6), change on suspected compromise (8.3.8), no reuse of the last four (8.3.7), and MFA where 8.4 requires it. Protecting the credential in storage and transit (8.3.2) applies to all of them. A credential written on a note under the keyboard meets none of this and is the commonest finding on a walk-through.