|
|
Subscribe / Log in / New account

PCI compliance

PCI compliance

Posted Oct 12, 2011 21:59 UTC (Wed) by rickmoen (subscriber, #6943)
In reply to: PCI compliance by corbet
Parent article: WineHQ database compromised

FWIW: As someone who's gone through many, many rounds of proving PCI compliance, I can say that, yes, it's a hassle proving, each time, that your installed version of a security-sensitive package includes backported fixes not reflected in its publicly scan-able version number. I've worked out a routine where I keep handy a canned response that I can quote to answer that objection, which I haul out each testing cycle, with only minimal use of everyone's time.

Rick Moen
rick@linuxmafia.com


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds