#PCI-DSS
PCI DSS prohibits storing CVV/CVC even if encrypted
Digging deeper ... how can Credit card *WITH* CVV be captured? Surely that's not possible in this day and age.

The wording ... having received as a customer, it feels like they try and slip the number "1.9 million" past us like a side issue.

This is maybe the most comprehensive breach I've seen.
September 18, 2026 at 11:56 AM
Hooray for PCI DSS rules!
September 27, 2026 at 1:26 PM
There are also a number of other new requirements that hopefully you've been doing anyway all along, but you need to add to your compliance documentation that you're doing them. Overview here: blog.pcisecuritystandards.org/pci-dss-v4-w...
PCI DSS v4: What’s New with Self-Assessment Questionnaires
In this Q&A with PCI Security Standards Council’s Director of Data Security Standards Lauren Holloway, we look at some of the key changes in the PCI DSS Self-Assessment Questionnaires (SAQs) for versi...
blog.pcisecuritystandards.org
May 14, 2024 at 10:17 PM
today in my inbox:

"hackmd is now SOC 2 compliant"

what's next, "gist proudly becomes ISO-14001"?
"towards a PCI-DSS notepad"?
June 12, 2026 at 7:24 AM
PCI DSS never allows keeping the CVV/CVC after authorization, encrypted or not (Req. 3.3.1.2, v4.0.1).

In Australia, PCI DSS is contractual, not law. But the Privacy Act (APP 11) still requires reasonable security, and a card-data leak can be a notifiable breach.
September 23, 2026 at 7:56 PM
Okay. This is like nine layers down in The Fuckery, but we ran into it while trying to resolve The Fuckery and it is a fucking massive change: The PCI DSS standards have *significantly* changed the way sites using third party payment services can demonstrate they meet the standards.
May 14, 2024 at 10:16 PM
Doing PCI-DSS compliance as a bit
May 10, 2024 at 3:23 PM
“PCI DSS has no Australian statutory backing”
there are never any significant penalties, and there is never any recompense, so why the fuck would anyone bother with data security when ensuring compliance is an expense
September 18, 2026 at 11:59 AM
like idk but i reckon pci-dss would have an interest in this
May 22, 2024 at 4:52 PM
Why? Stripe isn’t storing your full card number either. They store last 4.

Stripe is used for a lot of actual payment systems.

Websites used to play fast and loose with CC info, that is why we now have PCI-DSS.
September 22, 2026 at 11:32 PM
Keeping card data and cvv in unsecure state is a breach of pci-dss regulations and should result in massive penalties and lose ability to accept further payment by cards.
September 18, 2026 at 11:50 AM
Mapping PCI DSS v4.0 to Real Attack Paths: How Modern Breaches Exploit Payment Environments

PCI DSS is designed to protect payment account data, but security teams should not look at the standard only as a checklist of individual requirements.

sisa.ai/resource/cyb...
Mapping PCI DSS v4.0 to Real Attack Paths: How Modern Breaches Exploit Payment Environments
Everything you need to know about Mapping PCI DSS v4.0 to Real Attack Paths: How Modern Breaches Exploit Payment Environments . Explained by Cybersecurity Experts.
sisa.ai
September 28, 2026 at 3:52 AM
Segundou preechendo o

Prioritized-Approach-Tool-For-PCI-DSS-v4-0-r1.xlsx

Dicas #bolhasec ?
October 7, 2024 at 2:43 PM
the credit card part alone could easily turn into a PCI DSS violation and i can only imagine the pants-shitting that would have happened if corporate had received an angry letter pointing this out
March 5, 2026 at 5:57 PM
-autsch- Shit... Warum wurde auch die CVV gespeichert? Zumindest nach PCI DSS ist das doch ein NoGo dachte ich
November 10, 2025 at 10:53 PM
Ale je to sranda, jak dlouho už můj cyklus řídí všemožné bezpečnostní audity, od ISO27001 přes SOC2 po PCI DSS.

Toho zobáka na fotce si nevšímejte, kde tomu je konec 🙂
October 17, 2025 at 12:06 PM
15+ yrs as an IT Systems Engineer

This violates so many DOD/HIPAA/PCI DSS IT security and credibility practices that are in place today. This makes Crowdstrike's issue look like a splinter next to a nuke crater. This needs to be documented for evidence and analyzed, if we ever get a chance.
February 3, 2025 at 7:18 PM
I thought a big selling point of stripe et al was that you didn’t need to worry about PCI-DSS as a simple merchant? 😭😭😭
May 14, 2024 at 10:37 PM
"AWS Compliance Programs: Understanding SOC, HIPAA, and PCI DSS" by Aditya Zalte

#compliance #cloud-security #security #monitoring
AWS Compliance Programs: Understanding SOC, HIPAA, and PCI DSS
A plain language look at the compliance programs AWS supports and what they mean for you.
community.aws
September 27, 2026 at 7:00 AM
"We think we've rebuilt all of Stripe in a weekend, please tell us what's missing before we push it live"

...but yeah, "experience with PCI-DSS a plus"
March 27, 2026 at 4:52 PM
That's a /pretty/ big PCI-DSS violation....
February 10, 2026 at 9:58 PM
eGovPod Podcast mit @egovpod.bsky.social und es geht schon am Anfang gut los... Thema wird PCI DSS in der Verwaltung werden.

Ja, startet witzig, wird aber auch n bisgen #Brandroden. Ist ja klar, nech?
August 26, 2024 at 6:08 PM
Anyone who does this would then lose their PCI-DSS certification and no longer be able to process credit cards if they let it make transactions without your approval. There are (or were) very strict rules in place about Credit Card transactions.
(20+ years in e-commerce as a software engineer)
April 28, 2026 at 6:35 PM
📦 intuitem / ciso-assistant-community
⭐ 1,387 (+50)
🗒 Python

CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential...
GitHub - intuitem/ciso-assistant-community: CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC, PSPF, GDPR, HIPAA, Essential Eight, NYDFS-500, DORA, NIST AI RMF, 800-53, 800-171, CyFun, CJIS, AirCyber, NCSC, ECC, SCF and so much more
CISO Assistant is a one-stop-shop for GRC, covering Risk, AppSec and Audit Management and supporting +70 frameworks worldwide with auto-mapping: NIST CSF, ISO 27001, SOC2, CIS, PCI DSS, NIS2, CMMC,...
github.com
January 2, 2025 at 10:01 PM