I have no idea where to go for PCI compliance questions, so I'd thought I'd give SO a shot. If someone can point me in the right direction of where I can go to ask questions, please share. I'll be happy to mark that as an answer as well.
If a PCI compliant site connects to a database that stores no user info, but does contain HTML and JavaScript snippets that could get rendered during the payment process, would this database need to have authentication to remain PCI compliant? I am evaluating MongoDB and found that it does not provide auth when configured with replica sets.
A several part answer:
Again, you might get some better answers over on http://security.stackexchance.com/ ...