9 points | by meysamazad 3 hours ago
4 comments
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
this article takes more time to read than dmarc takes to implement
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.
Sounds silly to me. A PAN should never even touch an employee's computer.
There are cases for card not present transactions, fraud and complex refunds but generally yes.
this article takes more time to read than dmarc takes to implement