The latest version of the Payment Card Data (PCI DSS) Security Standard, 4.0, brings significant updates compared to the previous 3.2.1 version. The aim of these changes is to improve the protection of payment data, adapt the standard to new threats, and increase flexibility for businesses. But what does this mean in practice?
1. Roles and responsibilities defined more clearly
One of the biggest changes is that roles and responsibilities must now be documented and understood at all levels. This applies in particular to:
-
Network security solutions
-
Maintaining secure configurations
-
Protecting cardholder data
-
Encrypting data transmissions
-
Access control and log monitoring
The previous version did not have such a detailed requirement. This means that companies must establish a clear division of responsibilities for handling information security tasks.
2. Tightened requirements for protecting card data
The storage and encryption of card data have been key requirements before as well, but now they are even stricter:
-
New rules regarding stored card data (SAD – Sensitive Authentication Data), especially for issuers.
-
Encryption requirements: SAD data must be encrypted before it is sent for authorization.
-
Technical controls to prevent copying of the card number (PAN) in remote access connections.
-
Cryptographic hashing requirements are now clearly defined.
-
Production and testing environment encryption keys must not be the same.
Previously, these requirements were not defined as precisely, which could have led to looser practices.
3. New requirements for encrypting data in transit
All PAN data (Primary Account Number) must now be transmitted only via validated certificates and you must maintain a list of all trusted keys and certificates.
In the previous version, there was no requirement for certificate validation, which meant that many companies might not have paid sufficient attention to this.
4. New requirements for malware protection and phishing
As information security threats increase, preventing malware and phishing has become even more important:
-
Risk-based assessment for systems that are not vulnerable to malware.
-
Continuous, regular malware scans.
-
Separate malware protection for USB flash drives and other removable media.
-
Mechanisms to prevent phishing attacks are now mandatory.
In the previous version, there were no specific requirements for combating phishing.
5. Secure development of information systems and applications
-
All custom applications must now be documented and inventoried.
-
Mandatory automated security protection is required for public websites.
-
Management of scripts on payment pages is now clearly defined.
Previously, secure application development practices were looser, which could have increased vulnerabilities.
6. Multi-factor authentication (MFA) for all CDE system users
Previously, multi-factor authentication (MFA) was required only for remote access, but now it is mandatory for all use of the CDE (Cardholder Data Environment) environment. In addition:
-
Account lockouts take effect after 10 failed attempts (previously 6).
-
The minimum password length is now 12 characters (previously 7 characters).
This means that all organizations using payment systems will have to significantly expand the use of MFA.
7. Improvements to physical access control
As regards physical security, the following is now required:
-
Automatic locking of consoles in critical areas.
-
Risk-based inspections of payment terminals (POI).
Previously, these were more recommendations than mandatory requirements.
8. Logging and monitoring requirements
-
Automated log review mechanisms are now mandatory.
-
Risk-based regular log reviews are required.
-
Failures of security controls must be responded to systematically.
In the previous version, log monitoring was largely a manual process.
9. Testing of security systems and processes
-
All vulnerabilities must be managed actively.
-
Authenticated internal vulnerability scans are now mandatory.
-
Service providers must support their customers in penetration testing.
-
Detection and prevention of malware channel intrusion.
This means that security testing is more systematic and more extensive than before.
10. Security policies and risk management
-
Annual technology assessment and documentation.
-
Risk-based approach to customized security methods.
-
Security awareness trainings expanded to be more comprehensive.
-
Response plans for unexpected storage of card data.
Previously, organizations’ security policies were more recommendation-based than the detailed requirements now defined.
What does this mean for businesses?
With these changes, PCI DSS 4.0 requires a more active and proactive approach to security management. This means:
-
Organizations must clarify their areas of responsibility.
-
Encryption and data protection practices will become significantly stricter.
-
Multi-factor authentication will become mandatory for all users of the CDE environment.
-
Log monitoring and security testing must be continuous and automated.
-
Malware protection and phishing protection have been raised as a key requirement.
In practice, this means that companies must update their cybersecurity strategy to meet the revised requirements, which may require new technologies, processes, and staff training.
Summary
PCI DSS 4.0 brings significant updates to the protection of payment data. The changes focus on clarifying roles, stronger encryption, risk-based security, and multi-factor authentication. Now is the time to ensure that your organization is ready for these requirements.
#Cybersecurity #PCIDSS #CardPayments