Understanding the PCI DSS prioritized approach to compliance
I read recently that a PCI DSS official recommended a "risk-based approach" to PCI that
allows for partial compliance by meeting the compliance obligations in stages. Is there such a
thing, and is it a practical way to achieve PCI compliance?