Critical Systems

PCIComplianceHubLast updated

The systems and technologies an entity judges to be of particular importance: those a business operation or a security function depends on. The Council's examples are security systems, public-facing devices and systems, databases, and anything that stores, processes or transmits cardholder data.

Applies to. Every entity, because several controls set their scope or their frequency by whether a system is critical: daily log review, timely patching, and change detection.
Example. An entity's list of critical systems includes its payment switch, its domain controllers, its firewalls and its internet-facing web servers. Logs from those are reviewed at least daily under 10.4.1; the rest may be reviewed at a frequency set by a targeted risk analysis (10.4.2).
Limits. The entity draws the line, and an assessor will ask to see the reasoning. Leaving a security system off the list to avoid daily review is the misuse the definition anticipates by naming security systems first. 6.3.3 requires critical vulnerabilities on any system to be patched within a month; 11.5.2 requires change detection on critical files; 12.10.1 requires the incident response plan to cover critical systems.
In PCI DSS v4.0.1. 10.4.1, 6.3.3, 11.5.2, 12.10.1