IT:AD:PCI:HowTo:PCI Scan Action List
- Related:
Summary
Process
The bare minimum steps are:
- Ensure 128 bit encryption or better:
- ie, disable SSL 2.0 Disable SSL 2.0
- Ensure that the certificates are issued from trusted SSL/TLS keys/certificates.
- In other words, if not using the browser, you have to do the work yourself of checking the trust chain (see how I did it for the KB mobile app).
There are further steps that can be done: * http://www.sslshopper.com/article-ssl-certificates-and-pci-compliance.html