What are some common challenges that companies face in trying to become compliant with PCI?
• No Intrusion Detection System (IDS) in place. • Logging and log management is not in place. • Failure of get Application Security reviews for applications that are used in the processing of credit card transactions. • Giving administrative access to too many users. • Lack of segregation between PCI and non-PCI networks. • Have not properly prepared for the financial and time investment required to become PCI compliant. • Failure to assign the proper number of employees to the PCI team(s) as needed to become and sustain compliance. • Failure to have unique login/passwords for all users. • Ensuring that administrative access is present on all user laptops connecting to PCI network. • No network DMZ in place.