Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Compliance, Regulations & Standardsarrow PCI Council Unveils Expected Changes for DSS Guidelines
EH-Net
May 23, 2013, 08:11:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: PCI Council Unveils Expected Changes for DSS Guidelines  (Read 15582 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« on: August 17, 2010, 08:57:33 AM »

By Dan Kaplan of SC Magazine on August 13, 2010:

Quote

The PCI Security Standards Council this week unveiled a summary of changes expected to appear in the upcoming release of a new version of its payment security guidelines.

Merchants and assessors should not expect any major revisions when version 2.0 of Payment Card Industry Data Security Standard (PCI DSS) is published Oct. 28, said Bob Russo, general manager of the PCI Council.

The five-year-old standard, which now will receive a refresh every three years instead of two, is expected to provide more clarification in certain areas, Russo told SCMagazineUS.com this week. The updates were based on "400 pieces of feedback" from the council's participating organizations.

"I think the nature of the changes is really a testament of the strength of the standard and that the standard is maturing at this point," Russo said.

Specifically, the new version will reinforce the need for retailers to conduct scoping exercises to locate all sensitive data prior to undergoing an annual assessment, Russo said. There are many low-cost discovery tools available that can be used to find cardholder information, which often lies in "obscure places in the network," he said.

In addition, the updated standard will detail a more risk-based approach for assessing vulnerabilities, Russo said. That means merchants can consider their own business circumstances when evaluating and prioritizing flaws in their networks.

Yet the biggest news from the changes may be what they did not contain. The standards are not scheduled to include any specific references to emerging technologies to protect cardholder data, such as tokenization, chip-and-PIN and end-to-end encryption.

"I think the reaction to what's missing is the most important part of this announcement because it will push the council to move faster on areas they have not yet," Avivah Litan, vice president and distinguished analyst at Gartner, told SCMagazineUS.com on Friday. "A lot of fundamental questions are still unanswered."

Russo said the council has created a number of special interest groups to study these areas, and they are on track to release guidance for chip-and-PIN by the beginning of September, end-to-end encryption by the end of September, and tokenization by the end of October.

Those technologies are receiving a lot of attention because they help reduce the scope of what merchants must comply with, Litan said.

"Clients will call in and say, 'What does tokenization get us in terms of PCI compliance?'" Litan said. "And you can never give them a clear answer because it's not addressed in the requirements."

Guidance on virtualization, another hot technology because of the cost savings and efficiency it presents, may be released by the end of the year, Russo said.

"There's more questions than answers," Litan said of the updates. "On the other hand, it looks pretty mild. What most people worry about is if it's going to be a lot more work."

Meanwhile, version 2.0 of the Payment Application Data Security Standard (PA DSS) also will be released in October. That standard lays out 14 requirements for software developers who build programs that process credit card payments.

Changes include support for centralized logging and better alignment with PCI DSS.


Original article and other PCI related articles can be found here:
http://www.scmagazineus.com/pci-council-unveils-expected-changes-for-dss-guidelines/article/176889/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #1 on: August 17, 2010, 09:34:41 AM »

Thanks for the heads-up, Don. I am unfortunately trying to get management's ear about the updated PCI requirements..

Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #2 on: August 17, 2010, 11:00:30 AM »

I'd fully agree with their concern about the 'what is missing', although, as a pentester, that's just one more thing I guess I'll go after, as I show them where they're lacking...  Job security, I guess...?   Wink
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.