On 2008-05-14 pete.hill_at_sit-up.tv wrote:
> I am currently running through a PCI program at my company and am
> looking for recommendations on an email encryption tool.
>
> We currently use a licensed version of Winzip, but I have heard that
> this may not be up to job as far as passing a PCI DSS audit is
> concerned.
>
> Is Winzip good enough?
No. Use either S/MIME or an OpenPGP implementation (namely GnuPG or PGP)
for e-mail encryption.
Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq
Received on May 14 2008