Council Releases New PCI DSS

Nov. 1, 2010

The PCI Security Standards Council (PCI SSC), the Wakefield, Mass.-based industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Transaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS), recently released version 2.0 of the PCI DSS and PA-DSS. The council said key revisions serve to reinforce the need for a thorough scoping exercise prior to assessment in order to understand where cardholder data resides; promote more effective log management in securing cardholder data; allow organizations to adopt a risk-based approach when assessing and prioritizing vulnerabilities that is based on their specific business circumstances; and accommodate the unique environments of small merchants to simplify their compliance efforts. The new standards are effective January 1, 2011, but validation against the previous version of the standard (1.2.1) will be allowed until December 31, 2011, according to the standards body. The standards, detailed summary of changes and supporting documentation can be downloaded here .