PCI compliance is a joke. That isn't even close to good enough. I'll break all your PCI compliant stuff trivially.
What’s your main issue ? The compliance audit being lax or the compliance not being assertive enough ?
What’s your main issue ? The compliance audit being lax or the compliance not being assertive enough ?