ISO 27001 asks for a system, PCI-DSS asks for specific controls
Contrasts ISO 27001's risk-management-system approach with PCI-DSS's fixed requirements, and teaches network segmentation as a PCI scope-reduction strategy.
Contrasts ISO 27001's risk-management-system approach with PCI-DSS's fixed requirements, and teaches network segmentation as a PCI scope-reduction strategy.