Hacker News new | ask | show | jobs
PCI DSS DMARC Requirement: What Section 5.4.1 Requires (dmarcguard.io)
15 points by meysamazad 8 days ago
5 comments

this article takes more time to read than dmarc takes to implement
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

Sounds silly to me. A PAN should never even touch an employee's computer.

There are cases for card not present transactions, fraud and complex refunds but generally yes.
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
two words: compensating control.

(But also setup dmarc)