Posts Tagged ‘PCI Compliance’
PCI DSS v4.0 Goal 4: Enhance validation methods and procedures
At a glance The main takeaway: PCI SSC has issued a 360-page supplemental Requirements and Testing Procedures document. This document provides QSAs extensive clarification and guidance to enhance validation methods and procedures for PCI DSS compliance reporting. Impact on your business: The PCI 4.0 Requirements and Testing Procedure document provides detailed guidance and explanations of…
Read MoreThe 4 Goals of PCI DSS v4.0
At a Glance The main takeaway: The PCI Security Standards Council released PCI DSS version 4.0 on March 31, 2022 to replace version 3.2.1. Businesses subject to PCI compliance must understand the significant changes in PCI 4.0 as they plan their transition from PCI DSS v3.2.1 to v4.0. This video is the first in a…
Read MorePCI DSS v4.0 Goal 2: Promoting security as a continuous process
At a glance The main takeaway: Historically, PCI has been viewed as a point-in-time compliance standard and this explains why many entities have not established capabilities to treat PCI security as a continuous 24×365 process. PCI 4.0 establishes new requirements across the data security standard for security to be managed as a continuous process. Impact…
Read MorePCI DSS v4.0 Goal 3: Increasing flexibility of methods to achieve security objectives
At a glance The main takeaway: PCI 4.0 provides two validation options for compliance with the DSS. The first is the Defined Approach, which is similar to PCI’s historic approach. The second validation option, or Customized Approach, requires entities to conduct targeted risk analysis, define and then deploy controls against each PCI requirement. Impact on…
Read MorePCI DSS v4.0 Goal 1: Continuing to meet the security needs of the payment card industry
At a glance The main takeaway: Since PCI DSS 3.2.1 was released in February of 2018, many significant advancements have occurred in both the technologies used to enable payments and the nature of security threats facing the industry. These advancements have driven the four overarching goals of version 4.0. This video outlines the first goal…
Read MorePCI Compliance Is Broken. The “Business as Usual” Mindset Holds the Key to Fixing It.
The typical approach to PCI compliance is high-drama, inefficient and ineffective. You don’t have to look far for proof.
Read More