PCI council set to release new security standard
May 14, 2008
WAKEFIELD, Mass. — The PCI Security Standards Council, a global, open-industry-standards body providing management of the Payment Card Industry Data Security Standard, has announced plans to release version 1.2 of the DSS this October.
According to a news release, the update is expected to enhance technical-compliance clarity for users. The updated version also expects to offer improved flexibility and address new and evolving risks and threats.
Since the distribution of version 1.1 in September 2006, the PCI Council has engaged industry retailers, vendors, EFT networks, POS developers, banks and others to address real-world threats. Using feedback from those groups, version 1.2 aims toincorporate existing and new best practices; provide scoping and reporting clarification ; eliminate overlapping sub-requirements and consolidate documentation; and enhance the questions glossary.
Feedback form the industry ensures that PCI DSS continues to evolve in a manner that reflects threats in the marketplace and increases cardholder-data security, the council says.