Wednesday, May 8, 2024
News
NEWS HOME
»
PRESS RELEASES

PCI Security Standards Council Publishes Minor Revision to PCI Data Security Standard
  SocialTwist Tell-a-Friend  
   


Date: 18-05-2018 1:20PM
Source: PCI Security Standards Council
Category: General, Internet, Cyber Security, Information Technology, Banking & Financial Services, Technology, It & Tech
Location: Wakefield, Mass., United States

Business Wire India

Today the PCI Security Standards Council (PCI SSC) published a minor revision to the PCI Data Security Standard (PCI DSS), which businesses around the world use to safeguard payment card data before, during and after a purchase is made. PCI DSS version 3.2.1 replaces version 3.2 to account for effective dates and Secure Socket Layer (SSL)/early Transport Layer Security (TLS) migration deadlines that have passed. No new requirements are added in PCI DSS v3.2.1. PCI DSS v3.2 remains valid through 31 December 2018 and will be retired as of 1 January 2019.

“This update is designed to eliminate any confusion around effective dates for PCI DSS requirements introduced in v3.2, as well as the migration dates for SSL/early TLS,” said PCI SSC Chief Technology Officer Troy Leach. “It is critically important that organizations disable SSL/early TLS and upgrade to a secure alternative to safeguard their payment data.”

The minor changes in PCI DSS v3.2.1 reflect how existing requirements are affected once the effective dates and SSL/TLS migration deadlines have passed so that organizations can accurately report how their implementations meet these existing requirements after 30 June. Specifically, the changes include:

  • Removal of notes referring to an effective date of 1 February 2018 for applicable requirements, as this date has passed.
  • Updates to applicable requirements and Appendix A2 to reflect that only POS POI (point of sale point of interaction) terminals and their service provider connection points may continue using SSL/early TLS as a security control after 30 June 2018.
  • Removal of multi-factor authentication (MFA) from the compensating control example in Appendix B, as MFA is now required for all non-console administrative access; addition of one-time passwords as an alternative potential control for this scenario.

The updates in PCI DSS v3.2.1 do not affect the Payment Application Data Security Standard (PA-DSS), which will remain at v3.2.

PCI DSS v3.2.1 and a summary of changes from v3.2 to v3.2.1 are available now in the Document Library on the PCI SSC website. Updated versions of the Migrating from SSL and Early TLS Information Supplement, Self-Assessment Questionnaires (SAQ) and SAQ Instructions and Guidelines will be published shortly to support PCI DSS v3.2.1.

For more information, read PCI Perspectives blog Q&A with Chief Technology Officer Troy Leach: PCI DSS Now and Looking Ahead.

About the PCI Security Standards Council
The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to increase payment security by providing industry-driven, flexible and effective data security standards and programs that help businesses detect, mitigate and prevent cyberattacks and breaches. Connect with the PCI SSC on LinkedIn. Join the conversation on Twitter @PCISSC. Subscribe to the PCI Perspectives Blog.



CONTACTS :

PCI Security Standards Council
Mark Meissner, +1-202-744-8557
press@pcisecuritystandards.org
Twitter: @PCISSC

More Press Releases

C3.ai Digital Transformation Institute Announces AI for Energy and Climate Security Grantees

Moody’s Launches Moody’s Moments Video Series Providing Insight into Corporate Strategy

IDEMIA Signs With Storstockholms Lokaltrafik “SL” to Launch the World’s First Ever Public Transport EMV White Label Cards

Celebrity Face: India's No.1 Platform for Aspiring Content Creators and Fans to Photoshoot with Top Celebrities

Tally Solutions Announces the First Edition of MSME Honours

Sourced from the Himalayan Regions, Moving to the Wonders of Australia - BOHECO Joins Hands with Spring Sciences Australia

Moneycontrol App's Monthly Active Users Six Times Larger Than Its Closest Competitor for May 2021 - Similarweb

Healthcare Cloud Unicorn, Innovaccer, Certified as a Great Place to Work® Company

The Nation Gears up for the First-ever Edition of National Poker Series, India

DXC Technology Welcomes Brenda Tsai as Chief Marketing and Communications Officer

Schlumberger New Energy and Panasonic Energy of North America Announce Strategic Collaboration on New Battery-Grade Lithium Production Process

Fashion Designer Sanjukta Dutta Contributes Towards the Vaccination Drive Held in Assam Under the Guidance of Honorable Chief Minister Dr. Hemanta Biswa Sarma

Western Union Accelerates Digital Money Movement for Postal Networks Worldwide

NMIMS School of Branding and Advertising Partners with 120 Media Collective and Advertising Standards Council of India

High-Touch Spectacles Now Made Virus Free by ZEISS DuraVision AntiVirus Platinum UV

IRM India Affiliate Announces Results for May 2021 Level-1 Examination

Wipro Annual Report 2021 on Form 20-F Available Online for ADS Holders

RSA Introduces Outseer, a Spinout of its Fraud & Risk Intelligence Unit, to Transform Customer Authentication and Accelerate Revenue for the Digital Economy

Abu Dhabi Based Tablez to Expand Upon Investment in India’s Toys Sector With Its Proprietary Brand

 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
INDIA WORLD ASIA
'Why are people in Odisha poor despite s...
BJP tears into Sam Pitroda, dubs his 'Ea...
Madhya Pradesh: Bus carrying EVMs, polli...
Sena (UBT) mounthpiece questions Cong le...
Setback for AAP in Punjab: Former Amrits...
AAP's Saurabh Bharadwaj questions Centre...
More...    
 
 Top Stories
STL well-positioned to deliver stro... 
The Convergence Foundation and Indi... 
Remedium Lifecare Limited Sparks In... 
MDI Gurgaon Student Arun Mehta Achi... 
Veg thali in India got dearer in Ap... 
Stock markets witness high volatili... 
How to Achieve High-Quality Product... 
Infosys to Accelerate Yunex Traffic...