4 ms·
Can we discuss how ridiculous PCI compliance is to require anti-virus softare? Particularly in mac OS where anti-virus software is the primary surface area for
by s_dev 7y ago
Can we discuss how ridiculous PCI compliance is to require anti-virus softare? Particularly in mac OS where anti-virus software is the primary surface area for introducing viruses.
Why hasn't this requirement been updated to somthing more sensible?
- reaperducer 7y agoFrom your mouth to God's ear. IT installed freaking Norton on all of my new Macs. Now I feel less safe, and I get the software nagging me all the time.
- GordonS 7y agoKeep in mind that PCI requirements only apply to machines within the cardholder environment - everything else is out of scope. What this means is that as long as you isolate your cardholder environment, you don't need to deploy AV across your whole company - only on those in scope. I'm not a huge fan of AV, but I do advocate for a layered approach to security, and have to concede that AV may have some value as a "last chance" layer if malware somehow manages to get past your other defences.