Changes to PCI Data Security Standard leave questions unanswered
PCI DSS 2.0 mostly about minor tweaks, analysts say
Computerworld - A new version of the PCI Data Security Standard scheduled for release later this year is likely to attract more attention for what it leaves unaddressed rather than what it changes, analysts say.
That assessment is based on a preview of proposed changes to the standard that was released today by the PCI Security Standards Council, the body that administers the Payment Card Industry Data Security Standard (PCI DSS).
The preview suggests that most of the changes in PCI DSS 2.0, which is scheduled for release in October, are going to be incremental in nature and unlikely to cause major headaches for companies covered by PCI.
Much of the emphasis in the new version appears to be on fleshing out and clarifying existing guidelines rather than on introducing new ones.
But the new standard appears to leave largely untouched several issues where companies are looking for more guidance from the PCI council, analysts said.
"The standard's revisions seem like a positive step and don't seem to impose a lot of extra work and unreasonable requirements on complying organizations," said Avivah Litan, an analyst at Gartner.
"But what is glaringly lacking is progress on the hard and most important issues, including the implications of adopting alternative technologies" on PCI compliance requirements, she said.
According to Litan, many Gartner clients are trying to understand whether their adoption of new technologies such as chip cards, tokenization and end-to-end encryption will limit the scope of their compliance requirements, Litan said.
But most of the clarifications around such issues have been left for special interest groups to figure out, she said. "These SIGs are not being held to any particular deadlines, and it's still unclear how their reports will fold into PCI requirements," she said.
The PCI Security Standards Council's guidance around virtualization technologies is another area that is going to be closely watched, said James Paul, senior vice president of delivery at Trustwave, which provides PCI assessment services for many of the largest retailers in the country.
"Overall, there are no big surprises here. There is certainly nothing in the proposed list that our clients will have a lot of heartburn addressing," Paul said.
Today's preview indicates that the new standard will offer new guidance on how the use of virtualization technologies will impact PCI compliance requirements, he said. But a lot will depend on the amount of detail that is provided in the new version of the standard, he added.
"I'm encouraged that they are giving some additional guidance around virtualization," Paul said. "But we just can't get enough concrete details fast enough."
Many Trustwave customers want to know today if their use of virtualization technologies will increase the scope of their PCI requirements, he noted. "It's an emerging technology. There are a lot of questions around it," Paul said. "There are a lot of people somewhat hesitant to dive into it until they see some guidance."
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts