4 ms·
I don't think that is true, if the access to decrypt packet captures adheres to PCI access controls why would that violate anything? So long as the decryption
by voidlogic 9y ago
I don't think that is true, if the access to decrypt packet captures adheres to PCI access controls why would that violate anything?
So long as the decryption of a packet capture happens on host in PCI scope, the user is a PCI user and their actions are directly traceable to that single user? People who run systems in PCI need to debug their production systems too...
- AaronFriel 9y agoThese are all important caveats, but I'd suspect that many/most network devices do not have the rigorous controls to enforce all of those requirements simultaneously. I am out of my element here, though.
- voidlogic 9y agoIts not so bad, you have some dedicated debugging PCI host that you ship your packet captures too (packet capture never leaves PCI), then you checkout necessary private keys (system with keys is in PCI and only lets PCI users do this) and have a debugging session.