What is PCI DSS Version 4?

Issue 5 2023 News & Events, Security Services & Risk Management


Johannes Briel.

A new version of the Payment Card Industry (PCI) Data Security Standard (DSS), a set of security standards developed to protect cardholder data and ensure the secure processing of payment, will become mandatory as of 1 April 2024. Version 4 completely replaces version 3.2.1 and introduces several significant changes that aim to enhance data security and address evolving threats. These include a risk-based approach, enhanced flexibility, scalability, and alignment with modern security practices, and greater emphasis on education and security awareness across the board.

These new requirements have a significant impact on any business that handles card payment information, and organisations need to be prepared ahead of time to ensure compliance when the old version of the standard is retired on 31 March 2024.

The key changes

There are a total of 49 new requirements in PCI DSS 4 and 64 total changes ranging from evolving requirements, clarification or guidance and structure or format of the standard. All changes are designed to ensure that the standard evolves and continues to meet the changing requirements of the payment card industry.

The aim is to promote security as a continuous process, rather than a once-off exercise, and as such, the new standard incorporates a more flexible approach ‘customised approach’ as an enhanced way for entities to meet the security objective of the control that addresses the risk and alternative validation methods for auditors.

Certain security controls will become mandatory, including web application firewalls and multi-factor authentication (MFA) for all interactions relating to cardholder data. Other elements include changes to password requirements to enhance security, authentication of internal vulnerability assessments and an increased emphasis on security awareness, particularly around phishing and social engineering. Training will also become mandatory for all employees under the new version of the standard. In addition, automation of log reviews has become a requirement, as there is simply far too much data for effective manual reviews.

Security is a journey, not a destination

It's important to understand that achieving and maintaining PCI DSS compliance is not a one-time event or a fixed state. It's an ongoing process that requires continuous effort, monitoring, and improvement. Here's why security is considered a journey.

Cybersecurity threats and attack techniques in the payment card space have evolved significantly as more businesses have moved online, and security as a continuous process has become essential to protect payment data, which has become an increasingly attractive target for cybercriminals. PCI DSS 4 aims to address this by mandating clearly defined and assigned roles and responsibilities for each requirement, for merchants and third-party service providers. The new standard also provides additional guidance to help entities better understand how to implement and maintain security.

Because security can no longer be a static framework, the new version of the standard also increases flexibility for organisations that use various methods to achieve their security objectives. This supports payment technology innovation and gives organisations the ability to adapt their security practices through targeted risk assessments and analysis. To support this, the customised approach offers enhanced validation methods and procedures.

Don’t go at it alone

With the new recommendations and requirements introduced in PCI DSS 4, it can be challenging to understand how it applies to your business. This is particularly true when it comes to cloud-based and hybrid environments, which add a layer of complexity. While it is possible to do this in-house if you have an internal security auditor, for most businesses this is simply not the case, and even so, would require a heavy lift in terms of understanding and interpreting the changes. Enlisting the help of a Qualified Security Assessor (QSA) can help to ease the transition and ensure that all areas are effectively covered.

A QSA can take you through a gap analysis to identify where changes to the standard will have an effect and require changes to be made. From there, they can compile a roadmap to remediate gaps and align with version 4, ready for its implementation. This is important in helping to clarify scope and understand the requirements for meeting the new standards, in terms of both process and technology. A QSA will also be able to conduct a mock audit to validate any changes made and ensure they can be adjusted and adapted to align with the new standard.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Showtime for Securex
Technews Publishing News & Events
We have once again reached the time of year when the security industry focuses on Securex. This issue includes a short preview, with more coming online and via our special Securex Preview news briefs. ...

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Igniting standards, powering protection
Securex South Africa News & Events Fire & Safety
Fire safety is more than compliance, it is a critical commitment to protecting lives, assets, and infrastructure. At Firexpo 2025, taking place from 3 to 5 June at Gallagher Convention Centre, that commitment takes centre stage.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
From the editor's desk: We’ve only just begun
Technews Publishing News & Events
The surveillance market has expanded far beyond the analogue days of just recording and/or monitoring screens. The capabilities of surveillance technology today extend to black screen monitoring with ...

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...