Remix.run Logo
PCI DSS DMARC Requirement: What Section 5.4.1 Requires(dmarcguard.io)
13 points by meysamazad a day ago | 6 comments
john_strinlai a day ago | parent | next [-]

this article takes more time to read than dmarc takes to implement

CodesInChaos a day ago | parent | prev | next [-]

> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

Sounds silly to me. A PAN should never even touch an employee's computer.

dogma1138 a day ago | parent [-]

There are cases for card not present transactions, fraud and complex refunds but generally yes.

yonatan8070 a day ago | parent | prev | next [-]

Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access

tptacek a day ago | parent | prev | next [-]

Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.

fragmede a day ago | parent | prev [-]

two words: compensating control.

(But also setup dmarc)