14 points | by meysamazad 4 days ago ago
6 comments
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
this article takes more time to read than dmarc takes to implement
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
two words: compensating control.
(But also setup dmarc)
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
this article takes more time to read than dmarc takes to implement
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
two words: compensating control.
(But also setup dmarc)