# A PCI Threat Model

DevFeed: [A PCI Threat Model](<https://devfeed.tech/articles/a-pci-threat-model-36929.md>)

Original publisher: [Read original article](<https://shostack.org/blog/pci-threat-model/>)

Author: Adam

Published: 2020-09-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

## AI overview

The article presents a threat model for PCI and argues that compliance requirements do not necessarily provide security when they are disconnected from specific threats. It discusses the relationship between threats, controls, and requirements, and suggests that explicit threat models can improve security standards.

## Source excerpt

Compliance isn't Security, oh and something I wrote.