13 points | by meysamazad a day ago ago
6 comments
this article takes more time to read than dmarc takes to implement
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
two words: compensating control.
(But also setup dmarc)
this article takes more time to read than dmarc takes to implement
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
two words: compensating control.
(But also setup dmarc)