Skip to the main content.
Contact
Contact

1 min read

PCI DSS Version 3.1 Has Arrived

PCI DSS Version 3.1 Has Arrived

The PCI Security Standards Council today published the expected update to PCI releasing these documents including some specific migration guidance:

Updates to the DSS Supporting documents like the ROC Reporting Instructions and to the PA-DSS Standard are expected to follow soon.

Some of the notable changes and guidance:

  • PCI DSS v3.0 will be retired June 30, 2015
  • All SSL and “early TLS” to be sunset by June 30, 2016 (see requirements 2.2.3, 2.3, 4.1)
  • Unacceptable secure session transport (all versions of SSL, TLS 1.0, and some implementations of TLS 1.1)
  • How to address SSL and early TLS in ASV scans
  • POS terminals and their receiving gateways can continue  to use SSL and early TLS after the sunset date provided it can be verified that the implementation is not susceptible to known exploits.
  • Clarifications on how to validate service providers and third party outsourcers
  • Added 3.4.e to ensure truncated and hashed PAN stored together cannot be used to reconstruct the original PAN
  • End-user protocols now includes the example of SMS (text messaging)
The Art of Reading a PCI Attestation of Compliance (AoC)

The Art of Reading a PCI Attestation of Compliance (AoC)

PCI Attestations of Compliance (AoCs) provide organizations with a tool that helps with the all-important aspects of third-party due diligence.  Yet...

Read More
Control Gap Vulnerability Roundup: March 4th to March 10th

Control Gap Vulnerability Roundup: March 4th to March 10th

This week saw the publication of 493 new CVE IDs. Of those, 58 have not yet been assigned official CVSS scores, however, of the ones that were,...

Read More
Control Gap Vulnerability Roundup: February 25th to March 3rd

Control Gap Vulnerability Roundup: February 25th to March 3rd

This week saw the publication of 442 new CVE IDs. Of those, 258 have not yet been assigned official CVSS scores, however, of the ones that were,...

Read More