No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Events
    • GRC Connect U.S.
    • Calendar
    • Submit an Event
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
    • On-Demand Webinars: Earn CEUs
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

New Payment Security Standards Call for Modern Approach to Data Discovery & Classification

PCI DSS 4.0 rollout begins in March 2024

by Erfan Shadabi
November 6, 2023
in Compliance, Financial Services
credit cards lined up

PCI DSS 4.0 is set to start its phase-in during the first part of next year, with full implementation to follow in 2025. That may seem like a way’s off, but as cybersecurity expert Erfan Shadabi explains, complying with the new standards may mean revolutionizing how you handle data.

Regulatory mandates for data security, protection and privacy are as common as they are difficult to manage for compliance teams. For financial services organizations, the Payment Card Industry Data Security Standard (PCI DSS) has a new update set to take effect partially in March 2024, with full implementation a year later in March 2025. This update, like all previous updates, will be in the pursuit of protecting and securing cardholder information for all major card brands. PCI DSS version 4.0 will replace the previous standards in a few different areas, and overall, it is meant to protect the security of cardholders and to reduce fraud and other cyberthreats related to personally identifiable information (PII).

But time is running out. While 2025 sounds far off now, the actual process of getting an entire organization up to standard could be very intensive if not approached correctly.

What’s new with PCI DSS v4.0?

Some of the areas that PCI DSS v4.0 addresses include the following:

  •  Scoping validation
  • Regular reporting standards
  • Classification of data by risk
  • Cardholder data transmission protection
  • Anti-phishing and social engineering attack considerations
  • Inventories of systems and applications
  • Authentication, password and encryption requirements

In an update like this, there are a plethora of aspects for payment industry organizations to consider as they strive to get their data practices in order and to mitigate noncompliance. By March 2025, these organizations must be fully compliant with all of the above and all other considerations as stated by PCI DSS 4.0.

This is no small feat. Achieving compliance in the face of these new and improved regulations requires the complex coordination of employees, teams, departments and various operations. In other words: the entire organization.

shopper paying for coffee with credit card
Compliance

Report: Few Companies Are Ready for New Payment Security Standards

by Staff and Wire Reports
September 15, 2023

Most companies are woefully underprepared to meet an approaching compliance deadline for updated payment security standards, according to a new report.

Read more

Data discovery and classification

How should these organizations go about reaching PCI DSS compliance? The answer is data discovery and classification. Think of it like a map that aids organizations to achieve and maintain compliance with data security and protection regulations.

Frequently, organizations undertake manual data discovery, which can be a mistake. This approach often leads to substantial data oversights due to the challenges of comprehensively identifying all the diverse locations where data may reside. Additionally, today’s interconnected systems make it increasingly difficult to track data effectively. Existing data tracking systems primarily focus on known data, which, while beneficial, leaves organizations vulnerable to compliance challenges, particularly when confronted with stringent regulations like PCI DSS v4.0, where unidentified data poses significant complications.

Start now

As PCI DSS 4.0 takes full effect in less than two years, it is important for organizations to begin their compliance journey now. The consequence of noncompliance is much too high for organizations to ignore these regulations or even be mildly lax about them. One example of a stunning noncompliance penalty was following a data breach in 2017 against Equifax. This resulted in more than $400 million to be paid in penalties.

Looking even more broadly, however, it is also true that an organization can be PCI compliant but may still be attacked by cybercriminals. For example, in 2018, the PCI-compliant airline British Airways was hacked. An estimated 400,000 individuals had their data compromised in this attack, and the company was fined despite compliance with set standards. 

Compliance is only one of the goals

The example of the British Airways hack shows why it is important that organizations under the purview of PCI DSS ought not only seek compliance but also to aim for organization-wide resilience and security for all data. In this case, a company’s data discovery and classification system can keep them informed and well-armed for the sake of being informed and well-armed. Every company should strive for this, as it will protect their data integrity and organizational strength in the long run. Seek compliance and above all, seek knowledge. 


Tags: Payment Card Industry Data Security Standard (PCI DSS)
Previous Post

Gartner: Cloud Concentration Rising on List of Risks

Next Post

With a Key Deadline Fast Approaching, Now Is the Time to Address Requirements for Data Transfers Outside of China

Erfan Shadabi

Erfan Shadabi

Erfan Shadabi is a cybersecurity expert at data security provider comforte AG, where he works to help organizations identify and understand cybersecurity risks to allow them to make better and more informed business decisions. Shadabi previously held marketing and technical positions at Hyundai, The Helsinki Times, Nokia and Lionbridge.

Related Posts

shopper paying for coffee with credit card

Report: Few Companies Are Ready for New Payment Security Standards

by Staff and Wire Reports
September 15, 2023

Most companies are woefully underprepared to meet an approaching compliance deadline for updated payment security standards, according to a new...

card payment standards

New Card Payment Security Standards Are Coming. What Do They Mean for Your Business?

by Uriel Maimon
September 7, 2022

In March, the Payment Card Industry Security Standards Council published Payment Card Industry Data Security Standard (PCI DSS) Version 4.0...

abstract 3d render of credit cards, which are governed by PCI DSS 4.0

Dissecting PCI DSS 4.0: How Companies Can Prepare to Achieve Compliance

by Chris Pin
September 22, 2021

In many spheres, PCI DSS is like the law of gravity: It affects just about everything. PCI DSS 4.0, the...

illustration of cybersecurity concept

VigiTrust Launches VigiOne Cybersecurity Compliance Platform for Managed Security Service Providers

by Corporate Compliance Insights
August 17, 2021

Easy-To-Use, Cost-Effective Solution Enables MSSPs to Keep Pace with Changing Regulations, Scale Effectively and Ensure Ongoing Compliance New York, NY...

Next Post
world map of china

With a Key Deadline Fast Approaching, Now Is the Time to Address Requirements for Data Transfers Outside of China

Available SQ

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment Sanctions SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2023 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Events
    • GRC Connect U.S.
    • Calendar
    • Submit an Event
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
    • On-Demand Webinars: Earn CEUs
  • Subscribe

© 2023 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT