PCI DSS's
Aligning with PCI DSS 4.0's new objectives
Today, ransomware is a multibillion-dollar business. So far, it has devastated a number of industries. The continued availability of weak security mechanisms and antiquated operating systems made these assaults and others like them possible. Malicious actors are likely to continue to attack a range of businesses with ransomware in the future. They’ll almost certainly target individual companies’ POS systems, as EMV chip cards have made data harvesting practically difficult.
Fortunately, by adhering to the PCI DSS, organisations can help protect cardholder environments from ransomware and other digital threats. PCI DSS was created by the PCI Security Standards Council to assist organisations in protecting cardholder data, with which, card issuers and banks are held less liable in the event of a data breach at a merchant.
PCI DSS Version 4.0
There is little information available about the new PCI DSS. By Q1-2022, the PCI Security Standards Council expects to complete version 4.0. However, we do know a few of the new standard’s objectives. These include the following:- As technologies and solutions evolve, the revised standard will continue to meet industry needs.
- PCI DSS v4.0 will aim to increase flexibility and compatibility with alternative security methodologies. (Historically, the standard has been high. It introduced file integrity monitoring (FIM) and vulnerability management (VM) in the past.)
- PCI DSS v4.0 will emphasise security as a continuous process, allowing organisations covered by the standard to maintain compliance over time.
- Finally, PCI DSS v4.0 will enhance validation methods and procedures to assist organisations in adhering to the standard.