PCI Council issues summary of standard changes
August 19, 2008
WAKEFIELD, Mass. — The PCI Security Standards Council, an open-industry-standards body providing management of the Payment Card Industry Data Security Standard, says changes to PCI DSS are expected in October.
An overview of the summary of changes, as well as frequently asked questions, can be found on the council's Web site.
According to a news release, changes to the standard include clarifications and explanations of the requirements, offering improved flexibility to address today's security challenges in the payment-card-transaction environment. The clarifications are expected to eliminate redundant sub-requirements, while improving scoping and reporting requirements.
When version 1.2 is released, supporting documents also will be updated and consolidated. Most importantly, version 1.2 does not introduce any major requirements to the existing 12 in place since the council's inception.
"Version 1.2 should be seen as an improvement, not a departure from tried and true best security practices," said Bob Russo, general manager of the council.
The council has established a lifecycle process that ensures PCI DSS is revised and updated on a two-year cycle.