PCI 4.0 - PSW #825

Published: April 17, 2024, 9 p.m.

Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) puts greater emphasis on application security than did previous versions of the standard. It also adds a new \u201ccustomized approach\u201d option that allows merchants and other entities to come up with their own ways to comply with requirements, and which also has implications for application security. Specifically, PCI DSS 4.0 requires that by March 31, 2025, more testing of public-facing applications related to payment processing or other activities be considered \u201cin scope\u201d for compliance. Generally, any system that touches payment-card data is in scope for PCI DSS compliance, whether or not the system or function is public-facing. We'll talk through what organizations should have gotten done by March 31, 2024, and what needs to happen by March 31, 2025.

Segment Resources: https://info.obsglobal.com/pci-4.0-resources

Show Notes: https://securityweekly.com/psw-825