PCI compliance
PCI compliance
Posted Oct 13, 2011 4:05 UTC (Thu) by k8to (guest, #15413)In reply to: PCI compliance by corbet
Parent article: WineHQ database compromised
I work for a vendor who sells software that is sometimes used as part of the PCI compliance picture.
It's all too familiar to hear from customers (from auditors) that their scan-thing found a red item. Usually these red items represent bugs in the scanners, but they don't care (neither the auditor, nor the customers).
Fortunately our software doesn't have to actually pass the test software (it doesn't touch the card stream). So I point out some of the clauses of PCI compliance that say they don't have to care, and suddenly they're happy.
Sigh.