techfiend wrote: » The reason for the confusion on AV is the requirements state "PCI DSS requires anti-virus to be installed on all systems that are commonly affected by malware." Which leads me to believe it refers to Windows specifically.
Regarding restricting physical access what would auditors see as sufficient? Key locked door and rack good enough or are they looking for typical datacenter security with man traps, security guards, biometric scans, etc.?
techfiend wrote: » The lack of detail in the official standard should really hurt it's reputation. Clearly some of it is auditor discretion.