Chapter 6

Final Thoughts

As you wade through the changes document for PCI DSS 3.1, you may notice that there were a few items mentioned there that are not mentioned in this text. For the sake of brevity, any requirements that had minor clarifications of intent were not included in the text (outside of the Third-Party issue because it needs reinforcing). The owner of the Standard is the PCI Security Standards Council, and all of the official documentation can be downloaded from their website at http://www.pcisecuritystandards.org/. For enforcement issues, check with your acquirer to work through the payment brands. For any interpretation issues, check with your QSA. The Council is not an enforcement arm, they don’t want to see your ROC, and they ...

Get PCI DSS 3.1 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.