Seven Deadly Sins of a QSA (Part 5) standard
How to Avoid a Made Up Requirement The only way to avoid a made up requirement is to ensure that there is material in the PCI DSS that supports a recommendation before a it’s made. There are two main areas where you can find information on how to handle strange situations—PCI DSS itself as well as the FAQ that can be found on the PCI Security Standards Council’s website. The “Navigating PCI DSS” series is also useful, but supplementary and cannot be assessed against. Any guidance taken from documents other than the PCI DSS should be written up as a compensating control where appropriate. Additional documentation such as Special Interest Group (SIG) whitepapers, do not indicate changes in the standard ...
Continue Reading