PCI-DSS compliance controls
PCI-DSS compliance controls provide enhancements that help you with payment card industry (PCI) compliance for your workspace.
PCI-DSS compliance controls requires enabling the compliance security profile, which adds monitoring agents, enforces instance types for inter-node encryption, provides a hardened compute image, and other features. For technical details, see Enable the compliance security profile. It is your responsibility to confirm that each workspace has the compliance security profile enabled.
The data plane enhancements that are discussed in this document apply only to the Classic data plane in your AWS account. The additional security controls and monitoring do not apply to serverless compute, which runs compute resources in the serverless data plane in your Databricks account. For example, these new controls apply to pro and classic SQL warehouses, but do not apply to serverless SQL warehouses.
Your Databricks account must include the Enhanced Security and Compliance add-on. For details, see the pricing page.
Your Databricks workspace is on the E2 version of the platform.
Your Databricks workspace is on the Enterprise tier.
Single sign-on (SSO) authentication is configured for the workspace.
Enabling the compliance security profile at the account level or for specific workspaces.
Enable PCI-DSS compliance controls
To configure your account or workspace to support processing of data regulated by the PCI-DSS standard, enable the compliance security profile. One of those steps includes contacting your Databricks representative. When you do so, also request the PCI compliance controls. You will receive additional information and agreements to sign. When ordering, you have the option to enable this functionality across all workspaces on an account, or only on individual workspaces.
Preview features that are supported for processing credit card payment data
The following preview features are supported for processing of processing credit card payment data: