PCI DSS v.40 – learnings from the South West’s leading PCI QSA

Pete Woodward, CEO and Co-founder, delivered a webinar last month about our experience’s with PCI V4.0. During the session, he covered the transition period and key changes to the PCI Standard, along with providing practical guidance based on real-world experiences for organisations that need to be compliant with PCI DSS v4.0.

Pete is our Cofounder and CEO, and he’s been a PCI Payment Card Industry Qualified Security Assessor (or QSA) for many years. That means Pete is one of only a very small number of people worldwide qualified to perform Payment Card Industry compliance audits and consultancy. So Pete really is ideally placed to help us explain the changes that are coming with PCI DSS v4.0.

Here is a recording of the session with an article summarising the session below:

The transition period for PCI DSS v4.0

As depicted in the image above, we’re well into 2023 and Version 4.0 is running concurrently with Version 3.2.1. This means you can go for compliance with Version 4.0 now.

Let’s highlight some crucial dates: on March 31st, 2024, Version 3.2.1 will be retired. Starting from April 1st 2024, Version 4.0 becomes the only active version of the standard, and it’s important to note that certain requirements for Version 4.0 will kick in immediately, so keep that in mind.

Additionally, there are upcoming future requirements, giving you a grace period until March 31, 2025. However, our top tip is to avoid waiting until the last minute. Don’t wait until 2025; start looking into those requirements right now.

So what does PCI V4.0 mean for you?

Well, if your renewal is on the horizon, it’s a good idea to aim for a Version 4.0 assessment and ensure compliance – we’ll delve into the reasons why shortly. However, if your renewal has recently passed and you find yourself needing to conduct a gap analysis against Version 4.0, this is the perfect time to understand your environment, grasp the changes within it, and commence planning.

We’ve assisted numerous companies with gap analyses, whether they’ve since transitioned to Version 4.0 or not, and can happily help you with this if it would be helpful.

Now, let’s explore some of the changes and what they mean.

Continuing to meet the security needs of the payment industry

The primary goal of PCI DSS is to meet the security needs of payment card providers. It boils down to securing card details and adapting security practices to evolving threats.

A notable change in Version 4.0 is the expansion of multi-factor authentication requirements. It’s not limited to administrators anymore; it now includes all standard users accessing the cardholder data environment.

Understanding the scope and identifying where users interact with the environment is key. Multi-factor authentication has become an industry standard, and it’s likely that most companies, if not all, are already incorporating it in some form.

Another significant change involves password requirements. Version 4.0 demands longer, more complex passwords—shifting from a minimum of seven characters to a minimum of 12 characters, including upper and lower case, numeric, and special characters. If your system can’t accommodate a 12-character password, you can revert to an eight-character one.

However, the requirement to change passwords every 90 days remains, creating a bit of a paradox. This contradicts the UK National Cyber Security Centre’s recommendation of sticking to long, complex passwords without frequent changes unless there’s a compromise. Passwords, as always, present a challenge with differing approaches and advice from different organisations.

For many organisations, especially e-commerce providers facilitating card payments through their websites, Version 4.0 introduces changes to ASV scans. While they weren’t a requirement under the old scope, ASV scans become crucial under Version 4.0.

Implementation of a technical control to alert any tampering technology on payment pages is also essential. Understanding how payment pages are delivered to clients—be it through an iFrame or a full URL redirect—is vital during this phase.

Promoting security as a continuous process

Another significant emphasis in Version 4.0 is on viewing PCI DSS compliance as a continuous process. While it has always been important, Version 4.0 places even more emphasis on the idea that security should be an ongoing, continuous process rather than a one-time test. The PCI Council encourages organisations to consistently evaluate security measures over time, acknowledging the dynamic nature of cyber security threats.

Why is this important? Well, ongoing security is undeniably crucial in safeguarding payment card data, we all know criminals never sleep. The risk is continually evolving, impacting your compliance.

Now, let’s delve into some key aspects. Firstly, there’s a clear emphasis on assigning roles and responsibilities for each requirement.

Even though full compliance with Version 4.0 isn’t mandatory until April 1, 2024, if you were to implement Version 4.0 today, certain controls, like roles and responsibilities, should be in place immediately.

Version 3.2.1 doesn’t delve deeply into the details of organisational roles and responsibilities. However, Version 4.0 introduces a more detailed approach, requiring a granular understanding of roles and their accountabilities within the organisation. For instance, a network manager’s role might evolve from a broad responsibility for secure connections to a detailed examination of their training, security understanding, and encryption knowledge. This level of granularity is crucial for effective implementation.

Version 4.0 brings about better guidance, moving beyond the straightforward “implement this” approach of version 3.2.1. The emphasis is now on providing organisations with more guidance to enhance overall security, not just for PCI DSS but across the board. It promotes good practices and improvements in security.

The reporting landscape has also evolved, with Version 4.0 front-loading a significant focus on scope. Before, version 3.2.1 had a more generalised approach to determining scope, but now Version 4.0 places utmost importance on getting the scope right.

Over-scoping could lead to unnecessary administrative burdens and higher costs, while under-scoping might miss crucial areas requiring protection.

Increasing flexibility for organisations using different methods to achieve security objectives

Flexibility is a key feature of Version 4.0, offering different methods for organisations to achieve compliance. One notable change is the allowance of group shared or generic accounts under exceptional circumstances, with proper business justification, authorisation by management, and a break-glass scenario. This introduces a level of flexibility not present in version 3.2.1.

Targeted risk analysis is another significant addition, empowering organisations to establish the frequencies of certain activities based on a customised approach. This is particularly beneficial for well-established organisations with embedded risk methodologies, allowing them to tailor their approach to align with their existing strategies.

Enhancing validation methods and procedures

Enhanced validation methods bring transparency and granularity to the Attestation of Compliance, providing a clearer understanding of the PCI compliance status and scope. Frequent pattern discovery tasks for e-commerce platforms, broader applicability for encrypted cardholder data and trusted networks, and other transparency measures contribute to a more informed validation process.

Audit log reviews, a daily manual task in version 3.2.1, now need to be automated in Version 4.0. This shift aims to reduce the reliance on human efforts and introduces the need for automated mechanisms to review audit logs effectively.

How are we approaching PCI compliance with our clients?

In our approach to PCI compliance with clients, we’re actively assisting with both version 3.2.1 and Version 4.0. Conducting Version 4.0 gap analyses helps clients prepare for upcoming changes.

For new renewals, deploying Version 4.0 is considered where feasible, keeping in mind the unique considerations of each client. While the migration to Version 4.0 may not be universal for all clients right now, the current period is crucial for all organisations to start examining potential solutions and understanding the impact on future data requirements within their specific contexts.

Why might we recommend Version 4.0 for renewals?

The decision to deploy Version 4.0 for renewals stems from the longevity of version 3.2.1 since 2018. Version 4.0 introduces significant improvements, incorporating feedback from various entities and QSA companies garnered through Request for Comments sessions. Over 6000 comments have influenced this new standard, which makes it a substantial leap forward.

However, the rapid pace of technological advancement means that what Version 4.0 entails today might differ considerably from its future iterations. The expectation is a swift evolution to Version 4.1 as technology continues its relentless progression. Currently, we’re conducting gap analyses on environments against Version 4.0, aligning security measures and reinforcing protection within the cardholder data environment.

The proactive push towards Version 4.0 intensifies at the start of 2024, where we’ll be focusing on helping all our clients achieve compliance with Version 4.0.

Some of the key blockers we’ve experienced

Several factors influence the decision to delay Version 4.0 adoption. Organisations deeply entrenched in their Version 3.2.1 journey may prefer continuity. Some struggle with immediate changes, like roles and responsibilities, or lack the necessary capabilities to meet the requirements of the new standard. Valid reasons exist for delaying Version 4.0 adoption, and understanding these client journeys is crucial.

Technical requirements outlined by PCI DSS for Version 4.0 pose challenges, with industry consultations underway to address them. The shift in tamper detection mechanisms, alerting staff to unauthorised modifications, adds a layer of complexity. Organisations are understandably cautious as they await clearer technical solutions and industry responses.

Some of our experiences

Requirement 12.9.x – if you use Service Providers you will need to see their AoC and Shared Responsibilities Matrix, which lays out which entity is responsible for which areas – or whether responsibilities are shared.

Req 12.3.1 – Targeted Risk Analysis – Methodology is in the form, and this acts as your guidance. This means you should have a risk methodology and a risk regime within your organisation, with a specific targeted risk analysis, as opposed to a traditional enterprise-wide risk assessment.

Some PCI DSS requirements allow an entity to define how frequently an activity is performed based on the risk to the environment. The targeted risk analysis focuses on those PCI DSS requirements that allow an entity flexibility around, for example, the frequency of testing of a control, which is decided based on the risk to the environment. So, periodically this now needs to be defined with justification against the risk analysis.

So what should you do?

We recommend that you start sooner rather than later, and look at the new standard and how these changes will affect you. It’s important to assess where you are now and create a roadmap with organisational goals, feeding the changes into any technical decisions you’ll be making over the next year or two.

Important things you should bear in mind

Even if you’re not aiming for compliance with v4.0 yet, or are already compliant with Version 3.2.1, you need to be aware of the changes and what they might mean for your organisation. For example, if you’ll be looking to procure new software or a new digital solution in the coming months, you need to ensure any that you consider are compliant with PCI DSS v4.0

How Securious can help

We can provide PCI DSS v4.0 Transition Audits & Plans to help you understand what you need to do to ensure your organisation is able to meet the requirements of PCI DSS V4.0 by the deadline next year.

We have experienced QSAs on hand, who are happy to talk through questions or concerns – just get in touch.

We would also be happy to deliver this webinar (or a bespoke one on PCI DSS v4.0) to your clients or members.

To summarise

A lot is changing with the introduction of PCI DSS v4.0. There’s plenty to do, but there is enough time to get there. But you need to act soon and start learning about the new standard as soon as possible – and keep in touch with us here at Securious, as we’re always happy to help.