Home > Security News > Next version of PCI DSS due in September
Security News:
EMAIL THIS

Next version of PCI DSS due in September

By Mike Mimoso, Editor, Information Security magazine
10 Apr 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

SAN FRANCISCO -- PCI Security Standards Council General Manager Bob Russo said merchants can expect the next revision to the Payment Card Industry Data Security Standard in September.

I can't really tell you if it's going to be a rev, or a new version number ... anything that gets changed is something you've got to address.
Bob Russo,
general manager, PCI Security Standards Council

"I can't really tell you if it's going to be a rev, or a new version number. In my mind, it doesn't really matter if it's a 1.2 or a 2.0; anything that gets changed is something you've got to address," Russo said. "It won't be anything too drastic. It will be based on input we've gotten over the last year and a half from all of our stakeholders."

Russo said some of the areas that will be tweaked or clarified will be around wireless implementations, application security and pre-authorization.

Russo is attending RSA Conference 2008, where thousands of IT security professionals have gathered this week. PCI and compliance issues are among top concerns of conference attendees.

Ongoing RSA '08 coverage:
SearchSecurity.com and Information Security magazine editors are in San Francisco to bring you the most detailed coverage of RSA Conference 2008. Check back often for the latest news stories, interviews, podcasts, videos and blog tidbits from one of information security's biggest annual events.
>>>Visit RSA Conference 2008

Russo said that the PCI standard lives on a two-year lifecycle, and the next version comes due in September. A beta version of the standard will be released in August to the council's 500 participating organizations, as well as all of the council's qualified security assessors for feedback. They'll have 30-45 days to look it over for a "sanity check," Russo said. "It's a pretty good checks-and-balances system."

Russo said that additional guidance and clarification will be available in May for requirement 6.6, which moves from best practice to mandatory on June 30. PCI 6.6 has been the subject of some confusion for merchants trying to interpret how it's written. . The section, which falls under the main heading of developing and maintaining secure systems and applications, covers the security of Web-facing applications. As of June 30, it will mandate that Web apps be protected against known attacks by either having custom code reviewed by a third party, or by installing an application-layer firewall in front of a Web app.

Podcast: Interview with Bob Russo of the PCI Standards Council
Security Wire Weekly: PCI assessors run amuck? Bob Russo, general manager of the PCI Security Standards Council, explains what the council is doing to ensure that compliance assessors don't try to force particular vendors and products on businesses as the condition for a passing grade. 
Download MP3 | Subscribe to Security Wire Weekly

"There are guidance documents coming out that will clarify a lot of this stuff before June," Russo said.

The council recently posted a new document on its site called Navigating the DSS, which goes through each of the requirements in detail, explaining the intent and how requirements can be met.

The confusion over 6.6 rests in the either-or nature of the wording.

"Personally, I'd love to see everyone go through on OWASP-based source-code review, but certainly, that's not going to happen," Russo said, referring to the expensive and time-consuming process of manual code reviews. "So the application firewall is probably the best thing to do, but there needs to be some clarification around what it needs to do. That clarification is coming; that's been the biggest question."



Tags: PCI Data Security StandardData Privacy and ProtectionIdentity Theft and Data Security BreachesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
PCI Data Security Standard
Chip and PIN adoption
Chip and PIN adoption serves lesson for U.S. payment industry
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Wireless network guidelines for PCI DSS compliance
Visa probes tokens, encryption for PCI card data protection
Feds push cybersecurity jobs, PCI DSS changes ahead.
Voltage, RSA spar over tokenization, data protection
Experts, vendors search for PCI's holy grail

Data Privacy and Protection
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Mass. Senate seeks to amend, weaken data breach notification law
Data Privacy and Protection Research

Identity Theft and Data Security Breaches
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Chip and PIN adoption serves lesson for U.S. payment industry
Group to shed light on secure identity management threats
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Visa probes tokens, encryption for PCI card data protection
University data breach exposes 163,000 women to identity theft
TJX thrives following breach, bucks sour economy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
PCI DSS (Payment Card Industry Data Security Standard )  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts