Frequently Asked Question

What does “one function per server” mean?
The intent of the one primary function per server requirement (Requirement 2 of the PCI DSS) is to ensure that your organization’s system configuration standards and related processes address server functions that need to have different security levels, or that may introduce security weaknesses to other functions on the same server. For example, a database, which needs to have strong security measures in place, would be at risk sharing a server with a web application, which needs to be open and directly face the internet.
Note: The specific sub requirement number(s) and terminology may vary depending on the version of the standard being used.
August 2022
Article Number: 1224
Related
Featured FAQ Articles
Most Recently Updated
-
Is the expectation that any PFI investigation initiated must result in a PFI Final Report?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?