Remember kids when setting up data security, don't be an Equifax.

Since they can't honestly answer yes to the data at rest question, it probably means the resting data was not encrypted.

How did these guys get put in charge? This is a basic data security standard.


    I want to know why the auditors of PCI didn't stick it up equifaxes ass

    Was that part of the system not under PCI compliance?
