A laser focus on PCI compliance
For the past few weeks, I’ve been knee-deep in PCI compliance. I have previously mentioned that although my company’s current credit card transaction volume doesn’t require a full PCI audit, we have made a business decision to get the full PCI Report on Compliance, which entails hiring a qualified security assessor (QSA), submitting evidence, conducting a variety of qualified penetration tests and assessment scans and ultimately having an auditor spend about a week on site reviewing evidence and conducting in-depth testing of the 400-plus controls.
To read this article in full or to leave a comment, please click here
leave a reply: