TechTarget.com/searchsecurity

https://www.techtarget.com/searchsecurity/tip/PCI-DSS-v40-is-coming-heres-how-to-prepare-to-comply

PCI DSS v4.0 is coming, here's how to prepare to comply

By Paul Kirvan

In the first quarter of 2024, PCI DSS v4.0 will go into effect, supplanting the current v3.2.1 PCI standard that has governed credit card transaction security since 2018.

The new version of PCI DSS was released In March 2022. Both versions will coexist until v3.2.1 is officially retired on March 31, 2024, in favor of v4.0. However, credit card companies and vendors that use credit card transactions have until March 2025 to demonstrate compliance with v4.0. This transition period provides the time necessary for organizations to update their systems, policies and procedures to achieve compliance with the updated standard.

What's new in v4.0?

The new PCI standard is expected to include support for the following:

The following are the 12 PCI DSS criteria:

  1. installing and maintaining network security controls;
  2. applying secure configurations to all system components;
  3. protecting stored account data;
  4. encrypting cardholder data;
  5. protecting systems against malware;
  6. developing and maintaining security systems and applications;
  7. restricting access to cardholder data on a need-to-know basis;
  8. using unique identifiers to all users with network and system access;
  9. restricting physical access to cardholder data;
  10. logging and monitoring access to networks and cardholder data;
  11. regularly testing systems and resources for security; and
  12. developing, implementing and maintaining information security policies and programs.

Organizations that adhere to the criteria will have an easier time complying with PCI DSS v4.0 requirements.

Who must implement version 4.0?

Any business, merchant or organization that handles cardholder data must comply with PCI DSS requirements. The standard also governs how data is processed by major credit card companies, among them Visa and Mastercard.

The specification divides organizations into the following four categories:

  1. Level 1. Organizations that annually complete 6 million or more transactions across all transaction categories.
  2. Level 2. Organizations that annually complete between 1 million and 6 million transactions across all categories.
  3. Level 3. Organizations that annually process 20,000 to 1 million transactions across all categories.
  4. Level 4. Organizations that annually process fewer than 20,000 electronic transactions each year and other businesses that each year complete fewer than 1 million transactions across all categories.

How to prepare for v4.0 compliance

Even though PCI DSS v4.0 isn't mandated just yet, now is the time to begin the work needed to demonstrate compliance with the new standard.

Here are 10 steps companies should be taking:

  1. Review and understand the updated requirements in version 4.0. Identify and understand criteria essential for achieving compliance.
  2. Compare existing policies, procedures and other security-related activities against the new version's requirements.
  3. Establish a team whose job is to update security activities, particularly policies, procedures, technologies and staff expertise needed to comply with version 4.0.
  4. Remove all unnecessary data from affected systems -- especially data considered sensitive -- to prevent damage or theft of the data.
  5. Ensure relevant systems are secure from unauthorized access by threat actors.
  6. Examine the network perimeter to identify threats and vulnerabilities that could result in breaches.
  7. Maintain vigilance over systems through ongoing monitoring and documentation of security activities.
  8. Review protocols for security levels of cardholder data to ensure its safety and availability.
  9. Verify all data security activities are regularly tested and updated as needed. Results should be documented and subsequent reports used for proof of performance during audits.
  10. Regularly brief senior management on work the security team is performing to ensure compliance.

PCI DSS v4.0, once implemented, will further fortify security measures designed to protect cardholder data from a variety of potential risks and threats. Look for more information about the new standard from the payment card industry, as well as from security organizations offering guidance and technologies aimed at supporting the transition to the new standard.

24 Aug 2022

All Rights Reserved, Copyright 2000 - 2025, TechTarget | Read our Privacy Statement