The latest version of the security standard for payment card data (PCI DSS), 4.0, brings significant updates compared to the previous 3.2.1 version. The aim of these changes is to improve the protection of payment data, adapt the standard to new threats, and increase flexibility for companies. But what does this mean in practice?
1. Roles and responsibilities more clearly defined
One of the biggest changes is that roles and responsibilities must now be documented and understood at all levels. This applies especially to:
-
Network security solutions
-
Maintaining secure configurations
-
Protecting cardholder data
-
Encrypting data transfers
-
Access control and log monitoring
In the previous version, there was no requirement this detailed. This means that companies must create a clear division of responsibilities to take care of information security tasks.
2. Stricter requirements for protecting card data
Storing and encrypting card data have been key requirements before, but now they are even stricter:
-
New rules regarding stored card data (SAD – Sensitive Authentication Data), especially for issuers.
-
Encryption requirements: SAD data must be encrypted before it is sent for authorization.
-
Technical controls to prevent copying the card number (PAN) in remote connections.
-
Cryptographic hashing requirements are now clearly defined.
-
Production and test environment encryption keys must not be the same.
Previously, these requirements were not as precisely defined, which could lead to looser practices.
3. New requirements for encrypting data transfers
All PAN data (Primary Account Number) must now be transmitted only via validated certificates and a list of all trusted keys and certificates must be maintained.
In the previous version, there was no requirement for certificate validation, which meant that many companies may not have paid sufficient attention to this.
4. New requirements for malware prevention and phishing
As information security threats grow, preventing malware and phishing has become even more important:
-
Risk-based assessment for systems that are not vulnerable to malware.
-
Continuous, regular malware scans.
-
Separate malware protection for USB drives and other removable media.
-
Mechanisms to prevent phishing attacks are now mandatory.
In the previous version, there were no specific requirements for preventing phishing.
5. Secure development of information systems and applications
-
All bespoke applications must now be documented and inventoried.
-
Mandatory automated security protection is required for public websites.
-
Management of payment page scripts is now clearly defined.
Previously, secure practices for application development were more relaxed, which could increase vulnerabilities.
6. Multi-factor authentication (MFA) for all CDE system users
Previously, multi-factor authentication (MFA) was required only for remote connections, but now it is mandatory for all use of the CDE (Cardholder Data Environment). In addition:
-
Account lockouts take effect after 10 failed attempts (previously 6).
-
The minimum password length is now 12 characters (previously 7 characters).
This means that all organizations using payment systems will have to expand the use of MFA significantly.
7. Improvements to physical access control
For physical security, it is now required to have:
-
Automatic console locking in critical areas.
-
Risk-based inspections of payment terminals (POI).
Previously, these were more recommendations than mandatory requirements.
8. Logging and monitoring requirements
-
Automated log review mechanisms are now mandatory.
-
Risk-based regular log reviews are required.
-
Failures of security controls must be responded to systematically.
In the previous version, log monitoring was largely a manual process.
9. Testing of information security systems and processes
-
All vulnerabilities must be actively managed.
-
Authenticated internal vulnerability scans are now mandatory.
-
Service providers must support their customers in penetration testing.
-
Detection and prevention of malware channel intrusion.
This means that information security testing is more systematic and broader than before.
10. Information security policies and risk management
-
Annual technology assessment and documentation.
-
A risk-based approach to customized security methods.
-
Information security awareness training expanded to be more comprehensive.
-
Response plans for unexpected storage of card data.
Previously, organizations’ security policies were more recommendation-based than the detailed requirements now defined.
What does this mean for companies?
With these changes, PCI DSS 4.0 requires even more active and proactive management of information security. This means:
-
Organizations must clarify their areas of responsibility.
-
Encryption and data protection practices will tighten significantly.
-
Multi-factor authentication will become mandatory for all users of the CDE environment.
-
Log monitoring and information security testing must be continuous and automated.
-
Malware prevention and phishing protection have been elevated to a key requirement.
In practice, this means that companies must update their information security strategy to meet the revised requirements, which may require new technologies, processes, and staff training.
Summary
PCI DSS 4.0 brings significant updates to protecting payment data. The changes focus on clarifying roles, better encryption, risk-based information security, and multi-factor authentication. Now is the time to ensure that your organization is ready for these requirements.
#InformationSecurity #PCIDSS #CardPayments