Hacker News new | ask | show | jobs
by scurvy 3079 days ago
PCI compliance had little to do with where you're hosted, but how you're hosted and what you do with data.

AWS is not a magical PCI compliance button.

1 comments

Theoretically, it isn't. In actuality, and in our experience, there are a lot of compliance standards where just saying "we're on AWS" gets you 90% of the way toward acceptance. Its mostly buzzword compliance.
That's just not true. Most of PCI compliance is documenting practices and operations. Have you even completed all various levels of compliance? Or have you just done one level?