DiscoverInfoSec InsiderPCI DSS – The Overlooked Systems
PCI DSS – The Overlooked Systems

PCI DSS – The Overlooked Systems

Update: 2025-11-27
Share

Description

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) at URM, offer their advice on the systems and controls that are often overlooked in relation to the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss: 



  • Why the PCI DSS covers systems that don’t store card data, such as DNS servers or time servers

  • Why time synchronisation (NTP servers) is a PCI requirement

  • How card data can leak through system logs and how this can be avoided

  • Printers, custom error messages, IoT devices – why they’re in scope and how to maintain compliance.


Ask Alastair and Tibor a question: https://www.urmconsulting.com/podcasts/pci-dss-the-overlooked-systems


 


If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider    


 


You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts    


 


Connect with us on LinkedIn    


 


Brought to you by URM, the UK’s leading information and cyber security specialists.  

Comments 
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

PCI DSS – The Overlooked Systems

PCI DSS – The Overlooked Systems

URM Consulting