Jeff Carolus
10-12-2009, 11:22 AM
I have a payment application that is being prepared for Pa-Dss and have many questions, but one specific now.
Are the Pa-Dss requirements in line with the Pci-Dss requirements for password changes, length, re-using paswords, lockouts, etc.. (8.5.9 - 8.5.15) I can see having these strict controls for networks and servers, but in my case there is no "administrative access" to cardholder data allowed by the payment application.
Thanks for any help.
Are the Pa-Dss requirements in line with the Pci-Dss requirements for password changes, length, re-using paswords, lockouts, etc.. (8.5.9 - 8.5.15) I can see having these strict controls for networks and servers, but in my case there is no "administrative access" to cardholder data allowed by the payment application.
Thanks for any help.