The intent of this requirement is to prevent an unauthorized person from using an unattended console/PC to gain access to the user’s computer and accounts, and potentially to the company’s …
Yes, however, PCI SSC recommends the use of PCI-listed P2PE solutions. Please reference FAQ 1158 regarding the use of PCI-listed P2PE solutions regarding PCI DSS.
The P2PE v1.1 standard applies only to third-party P2PE solutions, where all encryption and decryption operations, and all cryptographic keys, are managed by a third party solution provider, and the …