3 ms·
That is more referring to the user/pass you might use to login retrieve card details say from a card vault for manual processing. Indeed PCI 3.1 (and actually f
by windowsworkstoo 10y ago
That is more referring to the user/pass you might use to login retrieve card details say from a card vault for manual processing. Indeed PCI 3.1 (and actually from v2) has a strong requirement for MFA when connecting to the cardholder data environment network.
I've lived PCI for a while - I don't think this particular issue would fall under their purview. As per PCI-DSS doc, it is primarily concerned with the secure "acceptance, transmission and storage" of cardholder data.
If they use a 3rd party payment processor for their credit/debit card transactions, they will only have a very limited PCI scope (probably just SAQ-A) which will basically say "oh, make sure you send it to your processor over TLS" and don't peek.
This particular instance is probably one for the regulatory body, which in our case in Aus would likely be APRA.