Share this
Previous story
← Phishing - Even the Security Folks get Targeted Part II
PCI DSS 3.2 is on the horizon with a release date expected to take place by the end of April. The PCI Data Security Standards is now considered a mature standard, which means that there will be incremental updates moving forward, not wholesale changes like we have experienced in the past. According to the PCI Security Standards Council, these changes occur for three main reasons:
While bullet points two and three sound similar, they are different, which we will see when we discuss the changes upcoming in PCI DSS 3.2. The PCI Security Standards Council has published on their blog a tentative timeline for releasing information about PCI DSS 3.2. Here is a snapshot of that timeline:
While we don't know all the specifics around the release yet, we have a pretty good idea of what changes will take place, when they will take place, and how long organizations will have to comply, which we will cover in this blog post. First, we need a quick history lesson on PCI DSS 3.1.
The big change in PCI DSS 3.1 was that SSL and early versions of TLS were no longer considered appropriate forms of cryptography according to the National Institute of Standards and Technology (NIST). The reason for this was due to some inherent weaknesses found in these protocols, exploited by browser attacks such as POODLE and BEAST. This was, and still is, a big change as this requires significant changes by organizations that would take some time to put in place. For that reason, it is no big surprise that one of the key changes in PCI DSS 3.2 has to do with the timeframe for moving away from SSL and Early TLS versions. So with that, let's hit on the 4 big changes in PCI DSS 3.2:
While that is a brief overview of the key changes, these are pretty significant in nature. For that reason, Compass will be holding a webinar on April 28th at 1:00 PM to discuss these changes and what they will mean for your organization. To register, click on the button below and we look forward to seeing you on the 28th!
What: Changes to the PCI DSS - PCI DSS 3.2
When: Thursday April 28th @ 1:00 PM EST
Where: Online, register below
These Related Stories
No Comments Yet
Let us know what you think