FAQ #1093 Diff

Does Requirement 3.4 apply to mainframes?

Earlier Version
Later Version
Removed
Added
Requirement 3.4 of theYes. PCI DSS Requirement 3.5.1 applies to mainframes that store cardholder data. If thea company has legitimate business or technical constraints toin meetmeeting this or any other requirement, compensating controls may be applied.considered. Compensating controls must beaddress commensurate withthe additional risk imposedintroduced by not adhering tomeeting the original requirement. Please refer

Refer
to Appendices B and C of the PCI DSS v4.0.1 for more information on the use ofabout compensating controls.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.