PCI DSS 2.0 "Preview"

August 13, 2010 Debbie Zaller

Yesterday, the PCI Standards Council posted a document highlighting some of the upcoming changes to the PCI DSS. That document can be found here.

The document is a “teaser” to what is expected to be released in the October timeframe. Two of the roughly four pages speak to the standards development process and feedback cycle. In addition, the Council itself notes that the updates" are relatively straightforward and do not introduce significant changes."

In terms of substantive previews, the following are worth noting:

  • Additional guidance is expected for cardholder environment definition and data flow mapping (i.e. scoping)
  • Guidance will be provided on virtualization (emanating from the Special Interest Group on this very topic) including how virtual components are defined "in-scope" as well as guidance on specific controls that were traditionally focused on physical hosts.
  • Updates to requirement 3.6 for key management to provide additional flexibility for new technologies and evolving ways to manage encryption keys.
  • Updates to vulnerability management and application security to reflect the evolving nature of those topics.

As with the last update, the devil will be in the details. The new standards are expected to be published in October and will become effective for all assessments performed starting in January 2011. At this time, there is no reason to believe that these changes will significantly impact the scope and cost of onsite assessments.

As always, if you have any questions, feel free to visit our PCI Resource Center or contact one of our QSAs .

About the Author

Debbie Zaller

Debbie is Principal and co-owner at Schellman & Company, LLC. She began her career in 2000 while working at Arthur Andersen in their Technology Risk Assurance practice. Debbie now leads the Midwest Region along with the Privacy, SOC 2 and SOC 3 service lines and is also on the AICPA’s SOC Specialist Task Force. She is responsible for internal training, methodology creation, and quality reporting. Debbie was a past member of the Florida Institute of Certified Public Accountants’ Board of Governors and served on the Finance and Office Advisory Committee. She also served on the AICPA’s Advanced SOC for Service Organizations Certificate Task Force.

More Content by Debbie Zaller
Previous Article
How to Overcome Common Hurdles to Maintaining PCI Validation
How to Overcome Common Hurdles to Maintaining PCI Validation

Every time a cardholder makes a purchase from you, or a merchant takes a transaction through your network o...

Next Article
PCI Resource Center Now Available
PCI Resource Center Now Available

Schellman & Company, Inc. has released a new resource center on our website for PCI information. Content in...