
PCI Requirement 9.8 – Destroy Media When it is no Longer Needed
Data Disposal Policies PCI Requirement 9.8 aligns with the methodology of many other PCI requirements: If you don’t need it, get rid of it. Remember PCI Requirement 3.1? It requires that organizations keep cardholder data storage to a minimum by implementing data retention and data disposal policies and procedures. PCI Requirement 9.8 is similar. It requires that organizations destroy media when it is no longer needed for business or…




