|
|
|
|
|
by mgkimsal
3568 days ago
|
|
So what can a developer do to their code to prevent someone in another part of a company from taking a phone call and writing down someone's credit card number? "Self assessed" or not, I'm failing to see how this can be prevented (or, more precisely, can be prevented by someone in the software development team). Not allowing certain IPs from entering credit card info at all? That's the only thing I can think of off the top of my head. |
|
You want to encourage your company as a whole, development and legal and everyone else, to take part in regular 3rd party audits and training around PCI Best Practices.
My point at the start of this was just that it doesn't do any good to dismiss this as "scammy" or think that one team can do this by themselves.
There's no "dev solution" here -- it's gotta be a company solution. (=