PCI_DSS_v4Requirement 2voice-validated

PCI_DSS_v4 R2: Requirement 2

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Malicious individuals (external and internal) often use default passwords and other vendor default settings to compromise systems. Apply secure configurations to all system components, with the goal of reducing the means available to attackers to compromise the system. This includes hardening, changing defaults, and removing or disabling unnecessary services.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 6

MitigationWhat it doesConfidence
M10511. Secure Configuration directly addresses PCI DSS Requirement 2 by mandating the application of hardened settings to all system components. 2. This prevents attackers from exploiting known default weaknesses.
95%
M10171. User Account Management, specifically changing default passwords, is a core component of PCI DSS Requirement 2. 2. This prevents unauthorized access via easily guessable or publicly known credentials.
90%
M10281. Operating System Configuration involves hardening systems and removing unnecessary components, as required by PCI DSS Requirement 2. 2. This reduces the attack surface and closes common exploitation vectors.
90%
M10341. Restricting Network Access by disabling unnecessary services is a direct mandate of PCI DSS Requirement 2. 2. This limits potential entry points for attackers and reduces exposure of system components.
85%
M10381. Privileged Account Management ensures default administrative accounts are secured or removed, aligning with PCI DSS Requirement 2. 2. This prevents attackers from gaining high-level access through default credentials.
80%
M10471. Audit mechanisms help verify that secure configurations, as per PCI DSS Requirement 2, remain in place. 2. This detects unauthorized changes to system hardening and default settings.
70%

Underlying weaknesses · 5

CWEWhy it persistsConfidence
CWE-13941. Use of Default Credentials is the primary weakness addressed by PCI DSS Requirement 2. 2. Attackers exploit these to gain initial access to systems.
95%
CWE-11881. Insecure Default Initialization of Resource directly relates to vendor default settings mentioned in PCI DSS Requirement 2. 2. These insecure defaults create vulnerabilities upon system deployment.
90%
CWE-7321. Incorrect Permission Assignment for Critical Resource often stems from default settings that grant excessive access. 2. PCI DSS Requirement 2 mandates hardening to correct such permissions.
80%
CWE-6681. Exposure of Resource to Wrong Sphere occurs when unnecessary services are left enabled by default. 2. PCI DSS Requirement 2 explicitly requires disabling these services to reduce exposure.
80%
CWE-2691. Improper Privilege Management can result from default accounts having excessive privileges. 2. PCI DSS Requirement 2's hardening guidelines aim to restrict such privileges.
75%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0182 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation