28/10/2010 -
The PCI Security Standards Council recently released version 2.0 of the PCI Data Security Standard and Payment Application-DSS, which will go in to effect starting January 1, 2011.The majority of the changes are clarifications of previous requirements to make them easier for merchants to follow and understand. The revisions reinforce the importance of knowing where cardholder data obtained through payment processing resides, effective log management in securing data, assessing vulnerabilities with a risk-based approach and simplifying compliance efforts for the unique environments of small merchants.
Additionally, the Council launched a new website to provide further information on how stakeholders can meet the requirements. There is also a site dedicated specifically to small merchants as part of a larger initiative to help this sector develop PCI security programs.
After meetings with key stakeholders, representing over 600 merchants, banks, processors, assessors and industry associations, the council constructed the new version.
"Feedback from our constituents is the lifeblood of the standards development process. The changes to the standards are a direct result of their input and underscore the strength of the standards as a framework for securing cardholder data," said Bob Russo, general manager of the PCI Security Standards Council.

We notice you are visiting from a U.S. Internet provider. 




