3 ms·
I thought PCI compliance required you to follow A standard (they didn't dictate which one) as long as it was a recognized industry standard and you were consist
by monkeywork 10y ago
I thought PCI compliance required you to follow A standard (they didn't dictate which one) as long as it was a recognized industry standard and you were consistent with it. NIST would qualify...
- CWuestefeld 10y agoWe're going through various audits for PCI right now. Our auditor insisted that we need to add checks for reuse of recent passwords. However, I've heard that the process varies widely depending on who your auditors are. Some are apparently very permissive, but we got the other end of the spectrum.