CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

PCI DSS Update | Avast

admin by admin
April 19, 2022
in Information Security
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Credit card issuers and online businesses will have two years to implement the changes.

Since we last wrote about Payment Card Industry Data Security Standards (PCI DSS), the organization has made a series of updates to its standards with its latest version 4.0. It contains several important improvements, which we’ll break down in this post.

What’s new in PCI DSS v4.0?

First off, the newest version of the PCI guidelines reflect that security has become a continuous process. This means that businesses will have more flexibility in how to achieve various security objectives, including how to quantify risks. One consequence of these changes is in the standards language around firewalls, which has been replaced by more general “network security” terms as well as a bigger emphasis on a more comprehensive zero-trust perspective. These items show the maturing of the standard and how data security practice has evolved over the past several years since the standard was first formulated.

PCI has partnered with Europay, Mastercard, and Visa to implement the use of the 3DS Core Security Standard during transaction authorization. This standard has already been implemented by the major credit card companies and goes by their brands such as Mastercard Identity Check, American Express SafeKey, and Visa Secure. The standard is designed to reduce fraud, particularly with online transactions, and embeds the authentication dialogs directly into the checkout workflows so that the purchaser would have a more frictionless ecommerce experience. The 3DS standards “will improve dynamic authentication for e-commerce and m-commerce environments as well as keep up with the increased usage of mobile payments and protect these transactions from fraud,” says Emma Sutcliffe of the PCI organization.

Perhaps the most important change is the expansion of encryption and MFA requirements to protect all accounts that have access to cardholder data.  The standards also require annual password changes, with 15-character minimums and a review of access privileges every six months. Taken together, this means better data protection but more work for businesses and banks to implement these tools.  

As you can see from the timeline graphic below, credit card issuers and online businesses will have two years to implement the changes, which will give them time to formulate their plans and test the new authentication and encryption processes.

While these changes are more evolutionary than revolutionary, there are some important takeaways for SMBs in particular:



Source link

Previous Post

CX, Hybrid Work, Hyperautomation, Ecosystems, and AI

Next Post

Control access to Amazon Elastic Container Service resources by using ABAC policies

Related Posts

Information Security

Conti Ransomware Operation Shut Down After Splitting into Smaller Groups

by admin
May 25, 2022
Information Security

Fronton IOT Botnet Packs Disinformation Punch

by admin
May 24, 2022
Information Security

Spring 2022 SOC 2 Type I Privacy report now available

by admin
May 24, 2022
Information Security

Tips to defeat social engineering attacks

by admin
May 24, 2022
Information Security

Yes, Containers Are Terrific, But Watch the Security Risks

by admin
May 24, 2022
Next Post

Control access to Amazon Elastic Container Service resources by using ABAC policies

Leave Comment

Recommended

The Best of SWL 2022 (SupportWorld Live)

May 25, 2022

Conti Ransomware Operation Shut Down After Splitting into Smaller Groups

May 25, 2022

Fronton IOT Botnet Packs Disinformation Punch

May 24, 2022

Spring 2022 SOC 2 Type I Privacy report now available

May 24, 2022

Tips to defeat social engineering attacks

May 24, 2022

Talent truth bombs and eye-opening stats from the 2022 MIT Sloan CIO Symposium

May 24, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.