PCI DSS DMARC Requirement: What Section 5.4.1 Requires

(dmarcguard.io)

14 points | by meysamazad 3 days ago

5 comments

  • tptacek 3 days ago
    Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
  • john_strinlai 3 days ago
    this article takes more time to read than dmarc takes to implement
  • yonatan8070 3 days ago
    Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
  • CodesInChaos 3 days ago
    > The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

    Sounds silly to me. A PAN should never even touch an employee's computer.

    • dogma1138 3 days ago
      There are cases for card not present transactions, fraud and complex refunds but generally yes.
  • fragmede 3 days ago
    two words: compensating control.

    (But also setup dmarc)