Hacker News new | ask | show | jobs
by pm90 834 days ago
This sounds like the worst version of SOC controls.
1 comments

It's all for "PCI Compliance" lol
How is it for PCI compliance? Which of the PCI DSS requirements outlines this?
Got me, first time I've ever had to fill out something like this
Section 6.5: "Changes to all system components are managed securely."

6.5.1 is probably where the CRF form came from.

There’s a lot you can do with ‘separation of responsibilities’.