UPDATE: PCI DSS v4.0 in Q1 2022
The PCI SSC announced that the planned completion date for PCI DSS v4.0 is Q4 2021. The council is seeking further feedback for PCI DSS v.4.0 validation documents and is holding Request for Comments (RFC) estimated for June 2021. More details on how to participate in the RFC will be posted in their blog.
We will also publish any updates on the PCI DSS v4.0 schedule changes as we learn from the Council.
PCI DSS Requirements
PCI DSS Requirement 5.4.1: Anti-spoofing controls such as DMARC, which stands for Domain-based Message Authentication, Reporting and Conformance, Sender Policy Framework (SPF), and Domain Keys Identified Mail (DKIM) can help stop phishers from spoofing the entity’s domain and impersonating personnel.
Clarification on eCommerce Outsourcing PCI DSS requirements 6.4.3 and 11.6.1
Unpacking the New PCI DSS Password Standards
Is Your Organization Prepared for PCI DSS Automation – Requirement 10.4.1.1?
What is the PCI DSS v4 Authenticated Scanning Mandate – Requirement 11.3.1.2?
What is the PCI DSS v4.0.1 Requirement for PoLP – Requirement 7.2.5?
The New PCI DSS v4.0.1 Software Catalog Mandate – Requirement 6.3.2
How to Analyze An Attestation of Compliance (AOC)
INFORMATION SECURITY PRIMERS
Primer on Post-Quantum Cryptography (PQC)
A Primer for AI Legislation and Litigation: Trends and Resources
A Primer to Frictionless Authentication
A Primer to Russian Intelligence “Snake” Malware
A Primer to Security Access Service Edge (SASE)
A Primer to Digital Risk Protection Services (DRPS)
A Primer to Cloud Access Security Brokers (CASB)
A Primer to Zero Trust Security
A Primer to Deception Technology
Managing AI Risks in Organizational Adoption and Usage