I completed a tedious PCI-DSS compliance exercise last year and now I know why we had so much trouble with the QSA. The PCI-DSS recommendations and guidelines were and still are out-dated! I suggest that on top of having annual review (are they doing that?) of the guidelines, they should also have a quarterly technology/process update to allow companies to adopt latest technology in their pursue to certify their IT environment.
Click to continue reading “PCI-DSS guidelines are not catching up with technology”