PCI Imposes New Payments Security Rules

On Thursday, April 28th, the PCI Security Council will be issuing its new payments security requirements. The new requirements are going to impose new rules, specifically surrounding authentication and third-party vendors (service providers and vendor management). The Thursday roll-out will insist on multifactor authentication (MFA) for all parties involved whose network access privileges might possibly enable them to touch payments data, regardless of job function. This is a change from previous requirements, which have only mandated multifactor authentication for people who work directly with payments data.
In addition to this requirement, third-party vendor companies who provide services to PCI-compliant organizations must also be PCI compliant, regardless of whether or not they are accessing payments data first-hand. The uniqueness about these changes stems from the Council’s recognition that protections must be implemented throughout all aspects of relationships and interactions with vendors. If a company provides services to a PCI-compliant customer, they should ensure that payment data access is restricted to unique users who are entirely segregated from the service provider’s entire network, or must comply with the Council’s requirements throughout their organization.
If you have any questions about PCI Compliance please contact Nate Gravel, Director of the Information Security Practice at ngravel@gravoc.com or W. Jackson Schultz, Security Consultant at jschultz@gravoc.com.
Related articles
The NSA Cybersecurity Guide for Remote Workers
In this blog post, we cover a few key recommendations for remote workers from the NSA guide, ‘Best Practices for Securing Your Home Network.’
GraVoc Recognized on CRN’s 2023 MSP 500 List
CRN®, a brand of The Channel Company, has named GraVoc to its Managed Service Provider (MSP) 500 list in the Pioneer 250 category for 2023!
The Cybersecurity Implications of ChatGPT
Is ChatGPT a security risk? In this blog post, we explore the cybersecurity implications of ChatGPT, including the benefits and challenges.