PCI DSS Compliance Solutions: Addressing 4.0 Requirements

Simplify PCI DSS 4.0 compliance efforts and protect cardholder data

PCI DSS 4.0 Requirements

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard that provides a baseline of technical and operational requirements designated to protect payment data and reduce credit card fraud. PCI DSS is intended for all entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD).

The new version of the standard was released on March 31, 2022. Changes from the previous version 3.2.1 include:

  • Expansion of Requirement 8 to implement multi-factor authentication (MFA) for all access into the cardholder data environment.
  • Updated firewall terminology to network security controls to support a broader range of technologies used to meet the security objectives traditionally met by firewalls.
  • Increased flexibility for organizations to demonstrate how they are using different methods to achieve security objectives.
  • Addition of targeted risk analyses to allow entities the flexibility to define how frequently they perform certain activities, as best suited for their business needs and risk exposure.

Details about the updates can be found in the PCI DSS v4.0 Summary of Changes document on the PCI SSC website.

Global

What is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage and enhance payment card account data security and facilitate the broad adoption of consistent sensitive data security measures globally. PCI DSS provides a baseline of technical and operational requirements designed to protect account data and be a part of an overall information security policy.

Compliance with the Payment Card Industry Data Security Standard 4.0 (PCI DSS)

Learn about compliance with PCI DSS 4.0, the latest update to the Payment Card Industry Data Security Standard, and how Thales can help secure cardholder data across hybrid IT environments.

Get the eBook

How Thales Helps with PCI DSS Compliance

Drawing on decades of experience helping banks and financial institutions comply with industry mandates, Thales offers integrated products and services that enable your organization to protect stored cardholder data, encrypt it for transfer, restrict access on a need-to-know basis and protect applications managing payment transactions. In addition, Thales works closely with partners to offer comprehensive solutions that can reduce the scope of your PCI DSS compliance burden.

PCI DSS

Addressing PCI DSS 4.0 Compliance Requirements

How Thales helps:

  • Discover, analyze and prioritize vulnerabilities.
  • Multi-Tenancy and separation of duties.
  • Encrypted Non-console administrative access.

Other key data protection and security regulations

PCI HSM

Global

MANDATE | ACTIVE NOW

The PCI HSM specification defines a set of logical and physical security compliance standards for HSMs specifically for the payments industry. PCI HSM Compliance certification depends on meeting those standards.

DORA

Global

REGULATION | ACTIVE NOW

DORA aims to strengthen the IT security of financial entities to make sure the financial sector in Europe is resilient in the face of the growing volume and severity of cyber-attacks.

Data Breach Notification Laws

Global

REGULATION | ACTIVE NOW

Data breach notification requirements following loss of personal information have been enacted by nations around the globe. They vary by jurisdiction but almost universally include a “safe harbor” clause.

Contact a Compliance Specialist

Contact Us