PCI DSS for universities – webinar recording

Pete Woodward, CEO and Co-founder, delivered a webinar last month to help universities understand how best to achieve and maintain PCI DSS compliance. During the session, he touched on the transition period for version 4, and explained the key changes to the PCI Standard, along with providing practical guidance based on his real-world experiences helping universities that need to be compliant with PCI DSS.

Pete has been a PCI Payment Card Industry Qualified Security Assessor (or QSA) for many years. That means Pete is one of only a very small number of people worldwide qualified to perform Payment Card Industry compliance audits and consultancy and has worked with a number of universities to help them achieve and maintain PCI compliance.

Here is a recording of the session with an article summarising the webinar below:

The countdown for PCI DSS Version 4 is on, with just a matter of days left until the official rollout on April 1, 2024. This transition marks a significant step forward in compliance and the future direction of PCI.

Over the past few years, extensive research and feedback from QSAs and industry experts have contributed to the development of version four. This iteration, the most substantial since 2018, is long overdue, considering the advancements in technology, processes, and procedures. 

When do I need to be compliant with PCI DSS v4.0?

PCI DSS V4.0 becomes the only active version of the standard PCI as of April 1, 2024. However, bear in mind that there are future-dated requirements, which will be applicable from April 1, 2025. This means there are some technical requirements in the new version of the standard that don’t need to be implemented immediately, so you have some time to make the necessary adjustments. 

If you’re currently running version 3.2.1 and your renewal is due before the transition period is over, you will remain on version 3.2.1 until your recertification date next year. However, if you’re planning to recertify, implement PCI compliance, or make changes within a new environment, it’s advisable to align with version four now.

What are the changes and what do they mean?

The whole point of PCI compliance is to enable organisations to continue to meet the security needs of the payment industry. Version four places a stronger focus on promoting security as an ongoing process, moving away from a single-point-in-time compliance model. This shift offers increased flexibility for organisations in submitting compliance, introducing both a defined approach and a customised approach. The latter allows organisations with established risk management processes to align their methodology with PCI compliance requirements.

What do we mean by complex environments? 

Universities and large organisations have complex environments. They generally come under three headings: technical complexity, organisational complexity, and compliance complexity. With technical complexities, you can have different networks – universities are going to have all sorts of projects going on. You’ll likely have a whole myriad of technical implementations around your campuses. 

Organisational complexity is all about people. It’s about parties and interested parties that need to run their PCI compliance programs, whether that’s finance, network security, compliance teams, etc.

Then you’ve got compliance complexity, which is about understanding your banking infrastructure, who your acquirers are, what sort of payment methods are taken, and the associated risk around capturing cardholder data and interacting with users and consumers of those card processes. 

One of the key things we work with universities around is understanding their complex environments. 

Addressing these complexities is crucial for effective PCI compliance. It requires thorough understanding, communication, and collaboration among stakeholders, considering the unique challenges posed by different departments, environments, and payment methods.

Common challenges include conflicting priorities, ownership of PCI compliance, and potential project slowdowns due to staff changes or organisational restructuring. To overcome these challenges, it’s essential to align stakeholders, streamline communication, and establish a unified approach to PCI compliance.

Questions

Our renewal isn’t due until later this year, after the transition deadline, but I don’t think we’ll be ready for version four by then. What should we do?

That’s a good question. Given that your renewal is later this year, and assuming you’re still on version 3.2.1, planning is crucial. Some changes, especially those related to e-commerce, aren’t applicable until April 2025. Focus on immediate changes like roles, responsibilities, and policy updates. It’s not all doom and gloom; prioritise the easy wins to ease the transition.

One of the challenges is defining the scope. Do you have any advice?

Version four emphasises scope, much like 3.2.1. Under-scoping risks leaving out critical elements, while over-scoping leads to increased costs and administrative burdens. Understand where you’re taking payments, payment methods, and all third-party service providers. Accurate scoping is the foundation; if you get that right, the rest falls into place.

Staff turnover is challenging. Any advice on maintaining continuity?

That’s a good question. Communication is key. Lack of communication is a common challenge in organisations. Establishing a bigger team with stakeholders from various roles, not just top-level positions, is crucial. This ensures that responsibilities for maintaining security are distributed and that there’s a continuity plan in place when staff changes occur.