What is PCI DSS Version 4?

Issue 5 2023 News & Events, Security Services & Risk Management


Johannes Briel.

A new version of the Payment Card Industry (PCI) Data Security Standard (DSS), a set of security standards developed to protect cardholder data and ensure the secure processing of payment, will become mandatory as of 1 April 2024. Version 4 completely replaces version 3.2.1 and introduces several significant changes that aim to enhance data security and address evolving threats. These include a risk-based approach, enhanced flexibility, scalability, and alignment with modern security practices, and greater emphasis on education and security awareness across the board.

These new requirements have a significant impact on any business that handles card payment information, and organisations need to be prepared ahead of time to ensure compliance when the old version of the standard is retired on 31 March 2024.

The key changes

There are a total of 49 new requirements in PCI DSS 4 and 64 total changes ranging from evolving requirements, clarification or guidance and structure or format of the standard. All changes are designed to ensure that the standard evolves and continues to meet the changing requirements of the payment card industry.

The aim is to promote security as a continuous process, rather than a once-off exercise, and as such, the new standard incorporates a more flexible approach ‘customised approach’ as an enhanced way for entities to meet the security objective of the control that addresses the risk and alternative validation methods for auditors.

Certain security controls will become mandatory, including web application firewalls and multi-factor authentication (MFA) for all interactions relating to cardholder data. Other elements include changes to password requirements to enhance security, authentication of internal vulnerability assessments and an increased emphasis on security awareness, particularly around phishing and social engineering. Training will also become mandatory for all employees under the new version of the standard. In addition, automation of log reviews has become a requirement, as there is simply far too much data for effective manual reviews.

Security is a journey, not a destination

It's important to understand that achieving and maintaining PCI DSS compliance is not a one-time event or a fixed state. It's an ongoing process that requires continuous effort, monitoring, and improvement. Here's why security is considered a journey.

Cybersecurity threats and attack techniques in the payment card space have evolved significantly as more businesses have moved online, and security as a continuous process has become essential to protect payment data, which has become an increasingly attractive target for cybercriminals. PCI DSS 4 aims to address this by mandating clearly defined and assigned roles and responsibilities for each requirement, for merchants and third-party service providers. The new standard also provides additional guidance to help entities better understand how to implement and maintain security.

Because security can no longer be a static framework, the new version of the standard also increases flexibility for organisations that use various methods to achieve their security objectives. This supports payment technology innovation and gives organisations the ability to adapt their security practices through targeted risk assessments and analysis. To support this, the customised approach offers enhanced validation methods and procedures.

Don’t go at it alone

With the new recommendations and requirements introduced in PCI DSS 4, it can be challenging to understand how it applies to your business. This is particularly true when it comes to cloud-based and hybrid environments, which add a layer of complexity. While it is possible to do this in-house if you have an internal security auditor, for most businesses this is simply not the case, and even so, would require a heavy lift in terms of understanding and interpreting the changes. Enlisting the help of a Qualified Security Assessor (QSA) can help to ease the transition and ensure that all areas are effectively covered.

A QSA can take you through a gap analysis to identify where changes to the standard will have an effect and require changes to be made. From there, they can compile a roadmap to remediate gaps and align with version 4, ready for its implementation. This is important in helping to clarify scope and understand the requirements for meeting the new standards, in terms of both process and technology. A QSA will also be able to conduct a mock audit to validate any changes made and ensure they can be adjusted and adapted to align with the new standard.

For more information contact Galix, 086 124 2549, [email protected], www.galix.com




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Pentagon appointed as Milestone distributor
Elvey Security Technologies News & Events Surveillance
Milestone Systems appointed Pentagon Distribution (an Elvey Group company within the Hudaco Group of Companies) as a distributor. XProtect’s open architecture means no lock-in and the ability to customise the connected video solution that will accomplish the job.

Read more...
From the editor's desk: AI and events
Technews Publishing News & Events
      Welcome to the 2024 edition of the SMART Surveillance Handbook. Reading through this issue will demonstrate that AI has undoubtedly made its mark on the surveillance industry. Like ‘traditional’ video ...

Read more...
Forbatt SA to distribute and support Tiandy in South Africa
Forbatt SA News & Events
The big news in this year’s SMART Surveillance Handbook is that Forbatt SA has signed a new distribution agreement with Tiandy Technologies. This brand has had limited exposure and support in South Africa in the past, but has posted significant growth internationally.

Read more...
Introducing the SecuShot Bullseye Robotic Guard MK2
Secutel Technologies News & Events Surveillance
The SecuShot Bullseye Robotic Guard MK2 is a marvel of modern engineering. It integrates CCTV monitoring, remote-controlled PTZ capabilities, and a gas-powered marker into a single, compact unit.

Read more...
Gallagher Security’s Integrate Roadshow
Gallagher News & Events
Gallagher Security recently teamed up with nine technology partners to showcase the latest integrated security capabilities at the Integrate Roadshow in Durban, bringing together about 60 attendees, including end users, channel partners, consultants, and other industry professionals.

Read more...
Ransomware impersonates employees and self-spreads
News & Events
Following a recent incident, the Kaspersky Global Emergency Response team is shedding light on an attack where adversaries crafted their own variant of encryption malware equipped with self-propagation capabilities.

Read more...
Level of RDP abuse unprecedented
Sophos News & Events
Cybercriminals abused Remote Desktop Protocol (RDP) in 90% of attacks handled by Sophos Incident Response in 2023, Sophos’ newest Active Adversary Report finds. External remote services were the number-one way attackers’ initially breached networks.

Read more...
Hexagon rebrands Qognify
News & Events
Hexagon’s Safety, Infrastructure & Geospatial division announced that Qognify has officially adopted the Hexagon corporate identity and fully integrated into the division as the physical security business unit.

Read more...
Five efficiency strategies for your security installation business
Securex South Africa News & Events
A recent conversation with one Securex South Africa 2024 exhibitor, led to the event organisers being able to share some advice on helping security installers make their businesses more efficient.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...