Hacker News new | ask | show | jobs
by Brystephor 833 days ago
How is it for PCI compliance? Which of the PCI DSS requirements outlines this?
3 comments

Got me, first time I've ever had to fill out something like this
Section 6.5: "Changes to all system components are managed securely."

6.5.1 is probably where the CRF form came from.

There’s a lot you can do with ‘separation of responsibilities’.