Diff: FAQ #1093

Does Requirement 3.4 apply to mainframes?

Earlier Version
2009-03-13 00:00:00 UTC
Later Version
2025-06-11 14:55:00 UTC
Removed
Added
Requirement 3.4 of theYes. PCI DSS Requirement 3.5.1 applies to mainframes that store cardholder data. If thea company has legitimate business or technical constraints to meetin meeting this or any other requirement, compensating controls may be appliconsidered. Compensating controls must be commensurate withaddress the additional risk imposntroduced by not adhering tomeeting the original requirement. Please r

R
efer to Appendices B and C of the PCI DSS for more information on the use of compensating controls.v4.0.1 for more information about compensating controls.