Well, for the most part, it's not like other regulations such as HIPAA and GLBA where many in management give it lip service but don’t really do much to comply. Generally speaking, it’s more along the lines of Sarbanes-Oxley 404 where, if companies slip up, there are real consequences. It is interesting how things like orange jumpsuits (SOX) and loss of credit card privileges (PCI) gets the attention of the powers that be.
That said, I have come across business managers recently that weren’t aware of PCI and others that thought it only applied if credit card data is stored locally (contradicting the “stored, processed, or transmitted” stipulation outlined in the PCI standard). Wow.





I think PCI DSS and Penetration Testing are all important ! And thank you to give so good idea!
ReplyDeleteI think PCI DSS and Penetration Testing are all important ! And thank you to give so good resources!
ReplyDeletepci compliance