Diff: FAQ #1224

What does one function per server mean?

Earlier Version
2009-07-07 00:00:00 UTC
Later Version
2022-08-16 19:44:00 UTC
Removed
Added
The intent of the one primary function per server requirement (Requirement 2.2.1 of the PCI DSS) is to ensure that your organization?s system configuration standards and related processes address server functions that need to have different security levels, or that may introduce security weaknesses to other functions on the same server. For example, a database, which needs to have strong security measures in place, would be at risk sharing a server with a web application, which needs to be open and directly face the internet.

Note: The specific sub requirement number(s) and terminology may vary depending on the version of the standard being used.