Hacker News new | ask | show | jobs
by jawspeak 6115 days ago
I've heard of companies having an internal policy: if in memory (in their data center's control) PCI sensitive data was allowed.

In some cases (memory mapped files) it could persist to disk, so either encryption, or a Compensating Control Document was created (limiting access to the filesystem).