InvestorsHub Logo
Followers 30
Posts 1459
Boards Moderated 0
Alias Born 09/08/2012

Re: WBCTrader post# 172223

Tuesday, 07/11/2017 10:03:31 AM

Tuesday, July 11, 2017 10:03:31 AM

Post# of 235130
Wrong - "MFA non Mandantory by PCI"

With Linking a PCI supplement with the link Text reading

"Non mandatory, or validated pci compliance"


That is not the name of the PCI Supplement


You are just Linking an Information Supplement by PCI and saying MFA is non Mandatory.

Try the actual Requirements where the rules are Listed.

MFA will be Mandantory for PCI Compliance in the Feb. 2018.

None the less, PCI Compliqnce is still not a Techincal Standard such as by a Technical Standards Body like ANSI.

Again, I'm all for OOB MFA Compliance by these Organizations.

But they are just a bunch of Rules that must be followed in order to be in compliance by the Credit Card Payment Processing Industry. The same as the FFEIC for banks.


thought guidance was not "mandatory". anyway looks like your PCI guidance is that, not mandatory.



Quote:
While PCI DSS Requirement 8.3 does not currently require organizations to validate their MFA implementation to
all the principles described in this guidance document, these principles may be incorporated in a future revision of the standard

but it might be one day, according to your Guidance you linked.
Non mandatory, or validated pci compliance