Friday, October 14, 2022

PCI DSS 4.0 Update - Everything You Need To Know




PCI DSS 4.0 is the latest version of the Payment Card Industry Data Security Standard. The latest upgraded standards are expected to be released anywhere between the end of 2020-mid 2021. Similar to all the previous versions of PCI-DSS, the latest upcoming version 4.0 will be a comprehensive set of additional new guidelines for securing systems involved in the processing, storage, and transmission of credit card data.

The latest version is a updated set of mature standards that focuses on an “outcome-based” approach rather than a “must-implement” based approach. So, while organizations will still have to meet PCI DSS standards, however, they will have the freedom to select their approach towards meeting those standards. Organizations will no longer be expected to meet PCI standards word by word. As long as they can meet the standards adopting a robust approach organization are good to go.

Let us today through this article understand the intention of rewriting the set PCI DSS Standards with additional requirements by the PCI Council. The article will clearly outline the intention and also highlights the key changes anticipated with the upgraded version of PCI DSS 4.0


What is the intention behind the PCI DSS 4.0 update?

While PCI DSS was is considered a fairly mature Standard, the intention to upgrade it with an updated version 4.0 is to meet the growing requirements of the evolving security threat landscape to the payment data. The following are four major reasons behind upgrading PCI DSS 3.21 to PCI DSS 4.0.


Ensure the standard continues to meet the security needs of the payments industry.

Provide flexibility and support of additional methodologies to achieve security. 

Promote security as a continuous process.

Enhance validation methods and procedures.

Upgrading from PCI-DSS 3.21 to PCI DSS 4.0

PCI-DSS 4.0 which is officially set to release anytime between the end of 2020 or early 2021 is expected to improve the existing PCI-DSS 3.2.1 version in a few ways.


1. PCI-DSS 3.2.1 which is the current standard includes a series of objectives and very specific and stringent requirements that outline how companies must achieve their goals of Compliance. In other words, the standard set is extremely onerous. So, businesses that are not able to follow these steps to compliance implement compensating controls. This is a tedious and time-consuming procedure that requires an organization to go way beyond their intended primary controls.


2. PCI-DSS 4.0 on the contrary intends to replace the existing compensation controls with an alternate option of adopting a customized implementation approach. This alternate approach allows the entity to design and develop their security controls to meet Compliance Standards. So, as per the latest version, the organization has to determine the security controls for a given objective and accordingly submit detailed documentation outlining the approach adopt to achieve compliance and demonstrate its effectiveness to the Qualified Security Auditor (QSA). Based on the analysis of the documentation submitted the QSA takes a final decision on the effectiveness of the control.


3. The use of Cloud and server less computing is another key area addressed in the PCI DSS version 4.0. The security controls of the existing Version 3.2.1 were not designed for the current IT landscape. Whereas the PCI DSS 4.0 is expected to introduce an updated set of requirements and approach to securing cloud and server less data. Learn here more about : PCI DSS and Cloud Security.


4. Businesses can also expect the introduction of new control requirements in context to the expansion of the encryption of cardholder data over any transmission within trusted networks. Moreover, one can expect additional control requirement updates pertaining to passwords/login access with multi-factor authentication.


Anticipated changes in the PCI DSS v.40

While the 12 core requirements of the PCI DSS will remain the same, several new requirements are set to be introduced. The new requirements are intended to address the evolving security threats to payment data. Further, to bring in better flexibility in terms of adopting an approach to achieving compliance new rules and requirements have been set. Going ahead, to understand the new changes, we have listed the key changes that are anticipated in the updated version PCI DSS 4.0 and what an organization can expect from these probable changes. 


Key Changes anticipated in the latest version PCI DSS 4.0

Flexibility in Implementing procedures

Introduction to Customized Implementation as a replacement to compensation control is one of the major changes expected to be introduced in the latest version of PCI DSS 4.0. The new approach shall define security outcomes for every security control requirement. With this new approach companies can comply by adopting a customized approach and showing their intent of the requirement is met without having to provide any operational or technical justification. This will enable more flexibility in implementation procedures and meeting requirements intent of Compliance. However, the company needs to provide a detailed document to the QSA justifying the effectiveness of control with a custom implementation. The QSA will have to validate the same by running thorough tests to ensure the effectiveness of controls and verifying whether the company is Compliant. 


free consulting


Stringent security requirements-

While several new requirements will be introduced in the latest version PCI DSS 4.0, the ultimate goal of PCI DSS shall continue to remain the same, which is ensuring all entities are compliant to the standard in context to securing cardholder data that is stored, processed, and transmitted. Assuming the establishment of a higher benchmark in comparison to PCI DSS 3.21, the PCI Council is set to restructure many requirements and include a much more stringent security standard for achieving Compliance. 


Multi-factor authentication

The PCI SSC has for long been working with the Europay, Mastercard, and Visa consortium to improve the authentication standards for both control process access logins and payment processes. Keeping this in mind, the latest PCI DSS 4.0 version may focus on the use of a 3DS Core Security Standard for secure transaction authorization. As per the 3DS standard, it enables an organization to build pluggable authentication options for enhanced security and customer authentication. This step will not just ensure that controls meet the regulatory requirements, but shall also enable scalability to the company’s evolving transaction objectives.


Data Encryption

Prevailing cybersecurity threats in the industry calls for a more secure cardholder data protection measure. One of the key challenges that need to be addressed involves the use of malicious code that penetrate the trusted network. To address this very issue, PCI DSS 4.0 will provide necessary measures and guidelines for adopting industry-best security practices. This will ensure secure network transmissions of cardholder data. 





No comments:

Post a Comment

Understanding SOC 2 Type 1 vs. Type 2: A Comprehensive Guide

  In today's rapidly evolving digital landscape, organizations are under constant pressure to demonstrate their commitment to security, ...