• Home
  • Subscribe
  • About
  • Archives
  • Search
  • Views
  • Bookstore
  • Careers
  • Consulting
  • Education

Version 1.2 of the PCI Data Security Standard Coming in October

Tags » Data Security, Merchants, PCI Compliance, PCI Security Standards Council

The PCI Security Standards Council has announced the timeline for the release of PCI DSS version 1.2, scheduled for availability in October 2008. According to the Council, the new version of PCI DSS will 'enhance the clarity of its technical requirements, offer improved flexibility and address new and evolving risks and threats.'

Since the distribution of version 1.1 of the Standard in September 2006, the Council has engaged industry stakeholders, including retail merchants, vendors, electronic funds transfer (EFT) networks, point-of-sale (POS) application developers, banks and other stakeholders with a global view to address real world threats and implementation challenges. Using feedback provided by this community, including more than 2,000 questions submitted to the Council since its formation in 2006, version 1.2 of PCI DSS:

  • Incorporates existing and new best practices
  • Provides further scoping and reporting clarification
  • Eliminates overlapping sub-requirements and consolidates documentation
  • Enhances the frequently asked questions and glossary to facilitate understanding of the security process

The enhanced clarity provided by version 1.2 will ease the implementation process and increase overall adoption of the standard. The updated standard will reflect the broad industry feedback and is designed to anticipate, identify and mitigate future security threats, but will not include any new core requirements beyond the existing 12 in place. This ongoing feedback process ensures that the PCI DSS continues to evolve in a manner that reflects threats in the marketplace and increases cardholder data security.

"We believe adoption of PCI DSS version 1.2 will increase cardholder data security and minimize the risk of data breaches that can challenge the positive public perception of the security practices of merchants and financial institutions involved in the payments chain,” said Bob Russo, General Manager, PCI Security Standards Council. “Version 1.2 will allow for the adoption of new best practices and protections with sufficient implementation lead time.”

Today’s announcement is the first in a series of public communications designed to raise awareness of the updated PCI DSS. Participating Organizations in the Council will have an opportunity to review the proposed changes at the PCI SSC annual Community Meeting to be held in Orlando, Fla., September 23-25, 2008.


Add your comment... (note that all comments are reviewed before they're published)

Sponsors

News View

Payments Consultants

Subscribe


  • or via RSS

Search

Languages



Glenbrook Partners

PAYMENTS NEWS IS PRODUCED BY AND IS A SERVICE MARK OF GLENBROOK PARTNERS, LLC
ISSN 1556-4487

Glenbrook's Consulting Services

  • Innovation and Strategy
  • Payments Product Development
  • Payments Market Assessments
  • Payments Vendor Selection
  • Merchant Payments Optimization
  • Payments Risk Management
  •  
  • To discuss how Glenbrook can
    help you
    , email us:

Glenbrook's Payments Education

  • Payments Boot Camp
  • Emerging Payments Roundtables
  • Special Focus Workshops
  • Private Payments Workshops
  •  
  •  
  •  
  • For more information on Glenbrook's payments education, email us:

Tools for Payments Professionals

  • Glenbrook Writings
  • Payments News
  • Payments Jobs
  • Payments Education
  • Payments Bookstore
  • Payments Glossary
  •  
  • To send us news that you'd like us to cover on Payments News, email us:

Contacts:                        
Compilation Copyright © 2002 - 2008 Glenbrook Partners LLC. All Rights Reserved.
Terms of Use        Privacy Policy        RSS Feed        Payments News RSS Feed

Subscribe to Payments News   

Follow Payments News on Twitter for Real-Time Updates