Recent FAQ Changes RSS

Latest changes to PCI SSC frequently asked questions.

FAQ 1135 New

Can VLANS be used for network segmentation?

In general, implementing adequate network segmentation can reduce the scope of the PCI DSS assessment if it isolates systems that store, process, or transmit cardholder data from other systems. While …

FAQ 1035 New

What is the definition of "remote access"?

PCI DSS requirement 8.3 is intended to apply to users that have remote access to the network, where that remote access could lead to access to the cardholder data environment. …

FAQ 1226 New

What is the role of the Advisory Board?

The role of the Advisory Board will be to provide strategic and technical guidance to the PCI Security Standards Council, reflecting different stakeholder perspectives. The Advisory Board does not have …

FAQ 1020 Updated

How does PA-DSS support a merchant's PCI DSS compliance?

Traditional PCI DSS compliance may not apply to payment application vendors since most vendors do not store, process, or transmit cardholder data. However, because these payment applications are used by …