Hacker News new | ask | show | jobs
by withinboredom 568 days ago
Yes. But it also isn’t a regulation. It is pretty much whatever you say it is.
1 comments

The problem is you need to be able to convince the auditor that your controls meet the requirement. That's a much easier discussion to have with robust logical or physical separation.