New PCI DSS details released

Powered by SC Magazine
 

Version 1.2 will contain no major new requirements.

Online traders could breathe a sigh of relief when the next Payment Card Industry Data Security Standard is released in October.

The industry-wide standard for all firms which store credit card data has had a mixed response since its launch in 2006.

But the new version will implement much of the feedback gleaned in the past two years, and aims to introduce more clarity, according to Bob Russo, general manager of the PCI Security Standards Council.

"Rather than releasing a totally new and updated standard this is a revision of 1.1, so there are no major changes to the way people have to comply with it, " he said.

"In the future, as we move to standard 2.0, there will more than likely be pretty major changes but [in this version] we've come up with a lot more clarity and consolidated a number of sub-requirements."

The only noticeable revisions to the standard are an explicit requirement to strongly encrypt all wireless transmissions of cardholder data across public networks according to industry best practice standards.

There is also a further prescription that any antivirus software applies to all operating system types and addresses all types of malware.

Russo added that there will be "no bumps in the road" between the two versions, so firms currently implementing 1.1 do not need to worry about changing their plans to accommodate the new standard.

Current proposals for DSS 1.2 are still being considered and a final version will be released in early October.

Copyright ©v3.co.uk


 
 
 
Top Stories
IBM, NEC picked for major NSW Transport deals
Final contract negotiations begin.
 
Westpac interim CIO resigns
Group CIO yet to be appointed.
 
Five emerging technologies that will transform financial services
[Blog post] Far out ideas that aren't far off.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  30%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  21%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 998

Vote