PCI on Employee Laptops
Hey guys. I sit on my company's CAB where I recently flagged a project as a potential expansion to our compliance scope due to what I feel like is a CHD-on-device situation (EUC devices are currently scoped out of our CDE). This project would require a small handful of users run an automation that would read CHD from the CDE, truncate the CHD, and then print the truncated string to a file to be shared with other employees.
If the CHD is being truncated at runtime, would that be an adequate control for the employee's laptop to be excluded from the CDE? My initial reaction is maybe? But only if we're able to baseline the automation and implement change monitoring over it (the risk being that someone may remove the truncation from the automation).