Requirement 1.4(b) asks if personal firewall software is not alterable by employee-owned computer users. If we allow employees to alter their personal firewall software settings, what other compensating controls could we implement in order to meet satisfy the objective of this requirement?
How does one become credited to do audits for PCI compliance .. what are the steps to be followed .. Does anyone know or understand the cost .. IS it a comp-any or an individual that gets a certificated or both ? what if the employees leaves does the company stay certified ?
We are thinking of acquiring a company which has a product which is not pci compliant. We are PCI-Compliant and want to Legally Segment the company so we can pass next years audit while we work to bring the other division into pci compliance. Would setting up a Holding company with two divsions work so [...]





