PCI DSS and Customized Approach Validation
With the new PCI DSS 4.0 updates now public, payment processors and security experts are examining some of the latest changes. One of the changes we’ve noticed (and one that will most likely make a massive difference for assessments) is the inclusion of customized approaches to PCI DSS assessment. This evolution of compensating controls in requirement assessment is set to alter how some companies think about their compliance obligations fundamentally.?
What Is PCI DSS Assessment?
Businesses that handle private cardholder data must undergo regular assessments from third-party assessment organizations. Organizations storing, transmitting, and processing cardholder payment and authorization information must undergo regular assessments by certified PCI DSS assessors to show that their IT infrastructures meet the minimum standard for compliance. These assessments are aligned with the 12 requirements and how they are defined in the PCI DSS 4.0 documentation.?
These assessors will evaluate businesses and their IT infrastructure on how they align with the 12 PCI DSS requirements:
With the unveiling of PCI DSS 4.0, there has been a slight shift regarding how companies can demonstrate their compliance with each requirement. Traditionally, there were well-defined capabilities that the company must show the assessor. Now, there is also a customized approach that they may take, depending on the circumstances.
What Is the Defined Approach for PCI DSS Validation?
The “defined” approach to PCI DSS validation under version 4.0 is much the same as it was under version 3.2.1–companies must provide evidence that they can meet the minimum expectation of each of the 12 PCI requirements.
Each requirement calls for one or more “defined approach requirements) that specify how the company can demonstrate their compliance with PCI DSS.?
Some of these requirements include:
These requirements break down in a particular level of granularity, from maintaining documentation on roles and responsibilities to implementing specific technologies and practices.?
More importantly, assessors must determine that these technologies, practices, and assets are properly implemented based on the company’s infrastructure, so some of the defined approach requirements will not stay identical from one organization to the next.??
Compensating Controls
Sometimes, an organization may not meet a PCI requirement as spelled out in the defined approach. In these situations, the PCI Council will allow for what’s known as a “compensating control,” or alternative technology or practice that effectively mitigates the risks that the original requirement was meant to address.?
Per PCI DSS guidelines, a compensating control must:
领英推荐
To implement a compensating control, the organization must provide a compelling business or technical justification.?
What Is the Customized Approach for PCI DSS Validation?
With technology and security evolving rapidly and with many companies adopting and deploying highly idiosyncratic infrastructures to handle customer data, the use of well-defined but rigid approaches to assessment doesn’t provide much wiggle room. Additionally, since PCI DSS allows for control alternatives based on customer needs, it seems logical to provide a framework for flexible compliance.?
PCI DSS 4.0 introduces the practice of “customized” compliance. This customized approach to assessment allows businesses to implement controls that align with their business and technical needs without strictly adhering to the letter of the law as described in the defined approach.?
Like compensating controls, customized approaches to compliance are expected to meet or exceed the defined PCI DSS requirement controls. However, they also call for the assessed company to interrogate their infrastructure and understand how they meet requirements without implementing specific controls. Likewise, assessors and businesses will work closely to develop testing and assessment criteria based on these customized approaches.?
Like defined approach requirements, each PCI requirement category includes a “customized approach objective” that states a broad goal that the custom control should address. Some of these include:
These customized approaches allow companies with the right know-how to use internally planned and configured IT towards PCI DSS compliance without double-up with other technologies.?
Note, however, that using the customized approach isn’t always the best thing to do. Smaller companies that don’t use tailored IT infrastructure and don’t need specialized security will benefit from the simplicity and clarity of defined approaches.
Conversely, larger enterprises with complex infrastructure and a firm grasp on their risk profile may find the customized approach superior for compliance and business goals.?
Get Ready for PCI DSS 4.0 Requirements with Lazarus Alliance
Whether you’re preparing for a well-defined PCI audit or want to explore customized approaches to compliance, you can trust the experts at Lazarus Alliance. We have decades of experience in compliance, security analysis, and audit support.?
Getting Ready for PCI DSS 4.0?
Call Lazarus Alliance at 1-888-896-7580