PCI DSS Minor Revision 3.2.1

25. May 2018

On 17 May 2018, the Security Standards Council (PCI SSC) published a minor revision to the PCI DSS. Revision 3.2.1 will become binding as of 1 January 2019 – version 3.2. remains valid through 31 December 2018.
The minor revision does not introduce any new requirements but eliminates confusion around effective dates and migration deadlines for SSL/early TLS.

The minor changes in PCI DSS v3.2.1 reflect how existing requirements are affected once the effective dates and migration deadlines for SSL/TLS (30 June 2018) have passed. The individual changes include:
• Elimination of notes referring to an effective date of 1 February 2018 for applicable requirements
• Updates to applicable requirements and Appendix A2 to reflect that only POS POI (point of sale point of interaction) terminals and their service provider connection points may continue using SSL/early TLS as a security control after 30 June 2018
• Removal of multi-factor authentication (MFA) from the compensating control example in Appendix B, as MFA is now required for all non-console administrative access; addition of one-time passwords as an alternative potential control for this scenario
The changes do not affect the Payment Application Data Security Standard (PA-DSS).


About the PCI Expert Tips:
With our PCI Expert Tips, we would like to keep you informed about changes to the PCI Security Standards and provide you with initial explanations as to what the changes entail and how they may affect you. Please take our articles as a general reference only – they do not replace individual case-by-case evaluations.
Should you have any questions or need assistance, please contact us. Our specialists are happy to help.
+49 6102 8631-190
sales@usd.de
Source: https://www.pcisecuritystandards.org/

Also interesting:

DORA Countdown: One Month Left Until the Deadline

DORA Countdown: One Month Left Until the Deadline

DORA, the Digital Operational Resilience Act, will fully apply as of 17 January 2025. We have summarized everything you need to know about the EU regulation, preparation and best practices from our news blog.

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

PCI DSS v4.0: In March 2024, version 4.0 of the Payment Card Industry Data Security Standard became mandatory after a two-year transition phase. Just a few months later, version 4.0.1 was released as a minor update of the standard, which will become mandatory on...

Top 3 Vulnerabilities in SSO Pentests

Top 3 Vulnerabilities in SSO Pentests

During their penetration tests (pentests), our security analysts at usd HeroLab repeatedly uncover vulnerabilities that pose significant risks to corporate security. They increasingly encounter the same vulnerabilities. Our blog series "Top 3 Vulnerabilities" presents...

Categories

Categories