Hacker News new | ask | show | jobs
by modoc 5877 days ago
One what? One person who's actually undergone multiple type 1 PCI audits? :)

Encrypting the credit card is the smallest part of it (although the number of people who actually pull off the encrypted key, key pieces kept by different people/systems, etc... is low). The networking, server, secure audit/logging to a dedicated server, patch within 90 days, policy documents, and so on are the hard parts.