Recent FAQ Changes

FAQ #1217 New

Does the PCI DSS apply to issuers?

PCI DSS applies to any entity that stores, processes, or transmits cardholder data and any such entity is expected to comply with PCI DSS, including issuers. However, each payment card …

FAQ #1115 New

How does PCI DSS apply to individual PCs or workstations?

All system components in the network are considered part of the cardholder data environment unless adequate network segmentation is in place that isolates systems that store, process, or transmit cardholder …

FAQ #1224 Deleted

What does one function per server mean?

The intent of the one primary function per server requirement (Requirement 2.2.1 of the PCI DSS) is to ensure that your organization?s system configuration standards and related processes address server …

FAQ #1093 New

Does Requirement 3.4 apply to mainframes?

Requirement 3.4 of the PCI DSS applies to mainframes that store cardholder data. If the company has legitimate business or technical constraints to meet this or any other requirement, compensating …

FAQ #1087 New

For ASV scans, what is meant by quarterly?

The intent of the quarterly scans as prescribed in Requirement 11.2 of the PCI DSS is to have them conducted as close to three months or 90 days apart as …