Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I assume you are referring to the NIST SP 800-63-3, which is quite new (still a draft).

PCI DSS follows NIST guidelines quite closely. Requirement 8.2.3 reads "refer to industry standards (e.g., the current version of NIST SP 800-63.)". These requirements will probably be updated at the next version of the standard (and I hope they will!).



Correct. Once the NIST draft is finalized, PCI standards will likely change quickly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: