Earlier quoted context omitted.
The company I work at has many PCI compliant systems. I asked a security officer why they were still doing certain things the old way. He explained they very well know it’s the old way but in order to be compliant they must do it.
I'm curious by what do you mean 'old way' for the very reason exposed above. Would you mind to give some examples?
do you write custom rules based on your actual application? <- not a real question