The new PCI DSS v4.0 version was published on March 31, 2022, by the Payment Card Industry Data Security Standard.
Organizations that process and handle credit card (CC) payments have until the first quarter of 2025 to adapt and fully comply with the 12 control objectives defined in this new version of the PCI DSS v4.0 standard. The current version will remain active until March 2024, and the new requirements will initially come into force from March 31, 2025.
Main objectives of the new version:
- Optimize control and validation techniques to achieve greater clarity in compliance information.
- Promote the use of security in all phases of the processes, emphasizing the importance of security. Stop seeing it as a product and start seeing it as a necessity.
- Improve security practices in the payment industry. These must transform as threats change.
- Provide greater flexibility and integration with other methodologies. Propose alternative paths or roadmaps to achieve the same standard.
This new version of PCI DSS v4.0, which is mandatory, brings greater clarity to the industry and removes the uncertainty that existed in previous versions.
On the other hand, it restructures its content and drafting format, with a clear definition of terms, thereby achieving greater guidance and understanding of them.
At the same time, it ensures that the standard is up to date with emerging technologies through its controls, protecting against risks, threats, vulnerabilities and changes occurring in the industry, thus reinforcing security as a continuous process.
New features and considerations to take into account in the new PCI DSS v4.0 version:
- It includes 64 new requirements, of which 11 apply to service providers, 53 to all entities and 51 are considered best practice.
- Roles and responsibilities. Clear assigned functions for each requirement, in addition to showing the customer’s responsibilities.
- Stricter authentication management. Identity and access management (IAM) plays a fundamental role in protecting cardholder data, and the new version of the standard recognizes this. It requires the use of multi-factor authentication (MFA) for all accounts that have access to cardholder data, not just for administrators accessing the cardholder data environment. The minimum number of digits will be increased from 7 to 12, while the number of lockout attempts will be increased from 6 to 10. PCI DSS requires that potential passwords be compared against the list of known bad passwords.
- Identify data flows by payment stage. Keep diagrams up to date and identify all locations where data is stored, processed and transmitted. Identify connections with third-party entities, etc.
- Risk assessment and monitoring. It is based on identifying the assets to be protected and controlling threats through automated event-detection processes.
- Testing, techniques and vulnerability scanning. Perhaps the most significant change: all internal vulnerability scans must be authenticated, the technology used must be reviewed periodically, and automated solutions must be implemented.
What are the 12 fundamental requirements for implementing the security controls?
The 12 PCI DSS requirements did not fundamentally change with the new version; they remain the fundamental pillar for protecting payment card data.
However, the requirements have been redesigned to focus on security objectives, to guide how the security controls should be implemented.
Main requirements to comply with:
- Install and maintain network security controls.
- Apply secure configurations to all system components.
- Protect stored account data.
- Protect cardholder data with strong cryptography during transmission over open public networks.
- Protect all systems and networks from malicious software.
- Develop and maintain secure systems and software.
- Restrict access to system components and cardholder data by business need to know.
- Identify users and authenticate access to system components.
- Restrict physical access to cardholder data.
- Log and monitor all access to system components and cardholder data.
- Test the security of systems and networks regularly.
- Support information security with organizational policies and programs.
In conclusion, it is a standard entirely based on the idea or mindset of Zero Trust. It reflects a complete evolution and helps organizations in the payment industry with regulatory compliance for the new emerging needs they face every day.
The ultimate goal of PCI DSS v4.0 compliance is to ensure that the standard continues to meet the constantly changing security needs of the financial services industry.
How Can We Help You?
At our company, we help you migrate to or implement the PCI DSS v4.0 security standard through the GlobalSuite tool, which offers you, among other advantages:
- Track compliance for each of the requirements
- Manage the corresponding evidence
- Save time across all processes by up to 40%
- Integrated reports for decision-making.
Start your path to success now. Request more information here
