This document discusses the need to audit and remediate IBM's WebSphere MQ middleware for PCI compliance. It notes that MQ installations commonly use the default, insecure configuration and outlines how this could allow unauthorized access. The document argues that auditors should assess MQ security because recent data breaches show attackers are targeting internal networks and middleware presents a potential vulnerability. It intends to explain why MQ security auditing is important and provide information on how to properly evaluate and remedy any issues found.