SlideShare a Scribd company logo
1 of 13
PCI DSS v3.2
The sooner you fall behind,
the more time you have to
catch up
Online Business Systems
Steve Levinson
Mark Hannah
This SlideShare summarizes a few of the key changes from PCI Data Security
Standard Version 3.1 to 3.2. It provides a high level view of the impact of
the changes on organizations subject to PCI requirements, based on Online
Business Systems’ QSA viewpoint. Many of the new sub-requirements will
remain as best practices until February 1, 2018.
PCI DSS v3.2
• Slide 3: Change Drivers for v3.2
• Slide 4: Important Dates
• Slide 5: SSL & TLS 1.0 – What we know
• Slide 6: SSL & TLS 1.0 – Mitigation
Strategy
• Slides 7-10: PCI Changes
• Slide 11: Six practical tips for avoiding
PCI failure
Table of Contents
Change Drivers for v3.2
• Improves prescriptiveness
• Scoping, data flow, and inventory
inconsistencies
• SSL TLS
• Third-party security challenges
• Slow self-detection, malware
• You’re only one change away from being out
of compliance
• Recent breaches
April28,2016
Summary of
changes
document, PCI
DSS 3.2, and ROC
reporting
template are
available on the
PCI SSC website
October31,2016
Version 3.1 will be
retired
All assessments
completed after
this date require:
• New 3.2 ROC
reporting template
and reporting
instructions
• New 3.2 AOCs
• Version 3.2 SAQs
February1,2018
Final date to
implement the
“Evolving
Requirements”
Important Dates
June30,2016
All service providers
must provide a
secure TLS service
offering
June30,2016
All entities must
have stopped use of
SSL/early TLS as a
security control,
and use only secure
versions of the
protocol.
SSL & TLS 1.0 – What we Know
SSL & TLS 1.0 – Mitigation Strategy
Plan A – Eradicate or target date
Plan B – Document, analyze and plan
• Inventory of all locations it is in use
• Data being transmitted for each implementation
• Documented risk assessment and RRMP
• May include compensating or mitigating controls
• Potential re-scoping issues
• Vigilance
• Change Control
• Appendix A2 – SSL/TLS Additional Requirements
PCI Council - INFORMATION SUPPLEMENT Migrating from SSL and Early TLS Version 1.1 Date: April 2016
2.1 – Changing vendor defaults and passwords
Updated to clarify payment applications are included in this
requirement.
3.5.1 – Documentation of their cryptographic architecture
Service Providers must create documentation of their cryptographic
architecture – this is a new requirement that is considered a best
practice until 2/1/2018.
6.2 – Payment applications
Security patches for all software including payment applications.
PCI Changes
6.4.6 – Infuse PCI DSS impact analysis into your change
management procedures
This new requirement (best practice until 2/1/2018) applies to ALL
assessed entities.
8.3.1 – All administrative access will require multi-factor
authentication (“MFA”)
This new requirement is probably the most robust change, and is a
best practice until 2/1/2018.
10.8 – Service providers must identify any critical security
control failures and respond accordingly
This new requirement will raise the bar for Service Providers (not
merchants) to improve their security event monitoring capabilities,
including monitoring the health of these functions.
11.3.4.1 – More frequent segmentation pen testing for
Service Providers
Increases the periodicity from once a year (or after ‘significant’
changes) to twice a year.
12.4 – Accountability!
Requires executive management to document PCI accountability,
create a charter for a PCI compliance program, and report updates to
executive management/board annually.
12.10.2 – Fine tune Incident Response Plan
Requires you to ensure that your annual IR test plan includes a
thorough review of all sub-elements from requirement.
12.11 – Service Providers must perform and document
quarterly reviews, best practice until 2/1/2018
12.11 Additional requirement for service providers only: Perform
reviews at least quarterly to confirm personnel are following security
policies and operational procedures. Reviews must cover the
following processes:
• Daily log reviews
• Firewall rule-set reviews
• Applying configuration standards to new systems
• Responding to security alerts
• Change management processes
Six Practical Tips for Avoiding PCI Failure
Slide from 2008 Presentation on DSS v1.2
The more things change the
more they stay the same
1. Store less data, and encrypt
or tokenize!
2. Understand your data flows
3. Address app and network
vulnerabilities
4. Improve security awareness
5. Monitor systems for
intrusions
6. Segment credit card networks
• Contact info:
• Steve Levinson
• Managing Director
• slevinson@obsglobal.com
• 619.701.8614
• Mark Hannah
• PCI Practice Lead
• mhannah@obsglobal.com
• 951.587.7991
To learn more visit our resource center:
http://info.obsglobal.com/online-business-systems-pci-3.2-resource-center
PCI Website: https://www.pcisecuritystandards.org

More Related Content

Viewers also liked

PCI DSS Reporting Requirements for People Who Hate PCI DSS Reporting
PCI DSS Reporting Requirements for People Who Hate PCI DSS ReportingPCI DSS Reporting Requirements for People Who Hate PCI DSS Reporting
PCI DSS Reporting Requirements for People Who Hate PCI DSS ReportingAlienVault
 
Continual Compliance Monitoring
Continual Compliance MonitoringContinual Compliance Monitoring
Continual Compliance MonitoringKimberly Simon MBA
 
Spirit of PCI DSS by Dr. Anton Chuvakin
Spirit of PCI DSS by Dr. Anton ChuvakinSpirit of PCI DSS by Dr. Anton Chuvakin
Spirit of PCI DSS by Dr. Anton ChuvakinAnton Chuvakin
 
Analysis of Market Opportunities for Indian Software Products
Analysis of Market Opportunities for Indian Software ProductsAnalysis of Market Opportunities for Indian Software Products
Analysis of Market Opportunities for Indian Software ProductsProductNation/iSPIRT
 
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIECVendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIECKimberly Simon MBA
 
PCI Compliance in Cloud
PCI Compliance in CloudPCI Compliance in Cloud
PCI Compliance in CloudControlCase
 
PCI DSS Essential Guide
PCI DSS Essential GuidePCI DSS Essential Guide
PCI DSS Essential GuideKim Jensen
 
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001ControlCase
 
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...Denim Group
 
Log Monitoring and File Integrity Monitoring
Log Monitoring and File Integrity MonitoringLog Monitoring and File Integrity Monitoring
Log Monitoring and File Integrity MonitoringKimberly Simon MBA
 
Introduction to Tokenization
Introduction to TokenizationIntroduction to Tokenization
Introduction to TokenizationNabeel Yoosuf
 
Various industry trends and career opportunities for engineering graduates in...
Various industry trends and career opportunities for engineering graduates in...Various industry trends and career opportunities for engineering graduates in...
Various industry trends and career opportunities for engineering graduates in...Dr. Shivananda Koteshwar
 
PCI DSS - Payment Card Industry Data Security Standard
PCI DSS - Payment Card Industry Data Security StandardPCI DSS - Payment Card Industry Data Security Standard
PCI DSS - Payment Card Industry Data Security StandardAlvaro Machaca Tola
 

Viewers also liked (20)

PCI DSS Reporting Requirements for People Who Hate PCI DSS Reporting
PCI DSS Reporting Requirements for People Who Hate PCI DSS ReportingPCI DSS Reporting Requirements for People Who Hate PCI DSS Reporting
PCI DSS Reporting Requirements for People Who Hate PCI DSS Reporting
 
PCI DSS and PA DSS
PCI DSS and PA DSSPCI DSS and PA DSS
PCI DSS and PA DSS
 
Continual Compliance Monitoring
Continual Compliance MonitoringContinual Compliance Monitoring
Continual Compliance Monitoring
 
Spirit of PCI DSS by Dr. Anton Chuvakin
Spirit of PCI DSS by Dr. Anton ChuvakinSpirit of PCI DSS by Dr. Anton Chuvakin
Spirit of PCI DSS by Dr. Anton Chuvakin
 
Pci dss v2
Pci dss v2Pci dss v2
Pci dss v2
 
Analysis of Market Opportunities for Indian Software Products
Analysis of Market Opportunities for Indian Software ProductsAnalysis of Market Opportunities for Indian Software Products
Analysis of Market Opportunities for Indian Software Products
 
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIECVendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
 
Software industry
Software industrySoftware industry
Software industry
 
Apakah PCI DSS
Apakah PCI DSSApakah PCI DSS
Apakah PCI DSS
 
PCI Compliance in Cloud
PCI Compliance in CloudPCI Compliance in Cloud
PCI Compliance in Cloud
 
PCI DSS
PCI DSSPCI DSS
PCI DSS
 
PCI DSS Essential Guide
PCI DSS Essential GuidePCI DSS Essential Guide
PCI DSS Essential Guide
 
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001
Log Monitoring and File Integrity Monitoring for PCI DSS, EI3PA and ISO 27001
 
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...
The ABCs of Source-Assisted Web Application Penetration Testing With OWASP ZA...
 
P2PE - PCI DSS
P2PE - PCI DSSP2PE - PCI DSS
P2PE - PCI DSS
 
PCI-DSS_Overview
PCI-DSS_OverviewPCI-DSS_Overview
PCI-DSS_Overview
 
Log Monitoring and File Integrity Monitoring
Log Monitoring and File Integrity MonitoringLog Monitoring and File Integrity Monitoring
Log Monitoring and File Integrity Monitoring
 
Introduction to Tokenization
Introduction to TokenizationIntroduction to Tokenization
Introduction to Tokenization
 
Various industry trends and career opportunities for engineering graduates in...
Various industry trends and career opportunities for engineering graduates in...Various industry trends and career opportunities for engineering graduates in...
Various industry trends and career opportunities for engineering graduates in...
 
PCI DSS - Payment Card Industry Data Security Standard
PCI DSS - Payment Card Industry Data Security StandardPCI DSS - Payment Card Industry Data Security Standard
PCI DSS - Payment Card Industry Data Security Standard
 

Recently uploaded

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 

Recently uploaded (20)

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 

What You Need to Know About PCI DSS v3.2

  • 1. PCI DSS v3.2 The sooner you fall behind, the more time you have to catch up Online Business Systems Steve Levinson Mark Hannah
  • 2. This SlideShare summarizes a few of the key changes from PCI Data Security Standard Version 3.1 to 3.2. It provides a high level view of the impact of the changes on organizations subject to PCI requirements, based on Online Business Systems’ QSA viewpoint. Many of the new sub-requirements will remain as best practices until February 1, 2018. PCI DSS v3.2
  • 3. • Slide 3: Change Drivers for v3.2 • Slide 4: Important Dates • Slide 5: SSL & TLS 1.0 – What we know • Slide 6: SSL & TLS 1.0 – Mitigation Strategy • Slides 7-10: PCI Changes • Slide 11: Six practical tips for avoiding PCI failure Table of Contents
  • 4. Change Drivers for v3.2 • Improves prescriptiveness • Scoping, data flow, and inventory inconsistencies • SSL TLS • Third-party security challenges • Slow self-detection, malware • You’re only one change away from being out of compliance • Recent breaches
  • 5. April28,2016 Summary of changes document, PCI DSS 3.2, and ROC reporting template are available on the PCI SSC website October31,2016 Version 3.1 will be retired All assessments completed after this date require: • New 3.2 ROC reporting template and reporting instructions • New 3.2 AOCs • Version 3.2 SAQs February1,2018 Final date to implement the “Evolving Requirements” Important Dates
  • 6. June30,2016 All service providers must provide a secure TLS service offering June30,2016 All entities must have stopped use of SSL/early TLS as a security control, and use only secure versions of the protocol. SSL & TLS 1.0 – What we Know
  • 7. SSL & TLS 1.0 – Mitigation Strategy Plan A – Eradicate or target date Plan B – Document, analyze and plan • Inventory of all locations it is in use • Data being transmitted for each implementation • Documented risk assessment and RRMP • May include compensating or mitigating controls • Potential re-scoping issues • Vigilance • Change Control • Appendix A2 – SSL/TLS Additional Requirements PCI Council - INFORMATION SUPPLEMENT Migrating from SSL and Early TLS Version 1.1 Date: April 2016
  • 8. 2.1 – Changing vendor defaults and passwords Updated to clarify payment applications are included in this requirement. 3.5.1 – Documentation of their cryptographic architecture Service Providers must create documentation of their cryptographic architecture – this is a new requirement that is considered a best practice until 2/1/2018. 6.2 – Payment applications Security patches for all software including payment applications. PCI Changes
  • 9. 6.4.6 – Infuse PCI DSS impact analysis into your change management procedures This new requirement (best practice until 2/1/2018) applies to ALL assessed entities. 8.3.1 – All administrative access will require multi-factor authentication (“MFA”) This new requirement is probably the most robust change, and is a best practice until 2/1/2018. 10.8 – Service providers must identify any critical security control failures and respond accordingly This new requirement will raise the bar for Service Providers (not merchants) to improve their security event monitoring capabilities, including monitoring the health of these functions.
  • 10. 11.3.4.1 – More frequent segmentation pen testing for Service Providers Increases the periodicity from once a year (or after ‘significant’ changes) to twice a year. 12.4 – Accountability! Requires executive management to document PCI accountability, create a charter for a PCI compliance program, and report updates to executive management/board annually. 12.10.2 – Fine tune Incident Response Plan Requires you to ensure that your annual IR test plan includes a thorough review of all sub-elements from requirement.
  • 11. 12.11 – Service Providers must perform and document quarterly reviews, best practice until 2/1/2018 12.11 Additional requirement for service providers only: Perform reviews at least quarterly to confirm personnel are following security policies and operational procedures. Reviews must cover the following processes: • Daily log reviews • Firewall rule-set reviews • Applying configuration standards to new systems • Responding to security alerts • Change management processes
  • 12. Six Practical Tips for Avoiding PCI Failure Slide from 2008 Presentation on DSS v1.2 The more things change the more they stay the same 1. Store less data, and encrypt or tokenize! 2. Understand your data flows 3. Address app and network vulnerabilities 4. Improve security awareness 5. Monitor systems for intrusions 6. Segment credit card networks
  • 13. • Contact info: • Steve Levinson • Managing Director • slevinson@obsglobal.com • 619.701.8614 • Mark Hannah • PCI Practice Lead • mhannah@obsglobal.com • 951.587.7991 To learn more visit our resource center: http://info.obsglobal.com/online-business-systems-pci-3.2-resource-center PCI Website: https://www.pcisecuritystandards.org