Today is the deadline for the future-dated requirements in PCI DSS v4.0 (now v4.0.1) to become mandatory. Until now they were considered best practice.
Key points
- Targeted risk analyses are required to set the frequency of certain controls.
- Multi-factor authentication is required for all access into the cardholder data environment.
- Scripts on payment pages must be authorised, inventoried and protected against tampering.
- Automated mechanisms are needed to review audit logs.
- Stronger password and authentication requirements apply.
UK merchants and service providers will be assessed against these requirements from now on. Any gaps should be addressed quickly, as they are likely to appear as findings in your next assessment.
Source: PCI DSS v4.x future-dated requirements (PCI Security Standards Council)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.