PCI_DSS_v4Requirement 2voice-validated
PCI_DSS_v4 R2: Requirement 2
PCI_DSS_v4
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Malicious individuals (external and internal) often use default passwords and other vendor default settings to compromise systems. Apply secure configurations to all system components, with the goal of reducing the means available to attackers to compromise the system. This includes hardening, changing defaults, and removing or disabling unnecessary services.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1051 | 1. Secure Configuration directly addresses PCI DSS Requirement 2 by mandating the application of hardened settings to all system components. 2. This prevents attackers from exploiting known default weaknesses. | 95% |
| M1017 | 1. User Account Management, specifically changing default passwords, is a core component of PCI DSS Requirement 2. 2. This prevents unauthorized access via easily guessable or publicly known credentials. | 90% |
| M1028 | 1. Operating System Configuration involves hardening systems and removing unnecessary components, as required by PCI DSS Requirement 2. 2. This reduces the attack surface and closes common exploitation vectors. | 90% |
| M1034 | 1. Restricting Network Access by disabling unnecessary services is a direct mandate of PCI DSS Requirement 2. 2. This limits potential entry points for attackers and reduces exposure of system components. | 85% |
| M1038 | 1. Privileged Account Management ensures default administrative accounts are secured or removed, aligning with PCI DSS Requirement 2. 2. This prevents attackers from gaining high-level access through default credentials. | 80% |
| M1047 | 1. Audit mechanisms help verify that secure configurations, as per PCI DSS Requirement 2, remain in place. 2. This detects unauthorized changes to system hardening and default settings. | 70% |
Underlying weaknesses · 5
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-1394 | 1. Use of Default Credentials is the primary weakness addressed by PCI DSS Requirement 2. 2. Attackers exploit these to gain initial access to systems. | 95% |
| CWE-1188 | 1. Insecure Default Initialization of Resource directly relates to vendor default settings mentioned in PCI DSS Requirement 2. 2. These insecure defaults create vulnerabilities upon system deployment. | 90% |
| CWE-732 | 1. Incorrect Permission Assignment for Critical Resource often stems from default settings that grant excessive access. 2. PCI DSS Requirement 2 mandates hardening to correct such permissions. | 80% |
| CWE-668 | 1. Exposure of Resource to Wrong Sphere occurs when unnecessary services are left enabled by default. 2. PCI DSS Requirement 2 explicitly requires disabling these services to reduce exposure. | 80% |
| CWE-269 | 1. Improper Privilege Management can result from default accounts having excessive privileges. 2. PCI DSS Requirement 2's hardening guidelines aim to restrict such privileges. | 75% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0182 compute · voice-rubric self-validated · 1 hallucination(s) dropped at validation