Recent FAQ Changes

FAQ #1135 New

Can VLANS be used for network segmentation?

In general, implementing adequate network segmentation can reduce the scope of the PCI DSS assessment if it isolates systems that store, process, or transmit cardholder data from other systems. While …

FAQ #1035 Deleted

What is the definition of "remote access"?

PCI DSS requirement 8.3 is intended to apply to users that have remote access to the network, where that remote access could lead to access to the cardholder data environment. …

FAQ #1226 Deleted

What is the role of the Advisory Board?

The role of the Advisory Board will be to provide strategic and technical guidance to the PCI Security Standards Council, reflecting different stakeholder perspectives. The Advisory Board does not have …

FAQ #1020 Deleted

How does PA-DSS support a merchant?s PCI DSS compliance?

Traditional PCI DSS compliance may not apply to payment application vendors since most vendors do not store, process, or transmit cardholder data. However, because these payment applications are used by …

FAQ #1079 New

What is the definition of "merchant"?

For the purposes of the PCI DSS, a merchant is defined as any entity that accepts payment cards bearing the logos of any of the five members of PCI SSC …