Starting Letter: P

PCI DSS Requirement 11.6.1

PCI DSS 11.6.1 Requirements

Deployment & Scope

A mechanism must be deployed to detect changes and tampering of HTTP headers and payment page content as received by the consumer browser, ensuring security and integrity at the point of consumption.


Detection & Alerts

Personnel must be alerted to any unauthorized changes, including modifications, additions, or deletions to security-related HTTP headers, as well as any changes or additions to scripts on payment pages.


Frequency

Evaluations occur at least once every seven days OR at defined periodic intervals as established by the organization's targeted risk analysis (TRA).

Penetration Testing (Pen Testing)

What is Penetration Testing (Pen Testing)?

Penetration Testing, commonly referred to as Pen Testing, is a simulated cyberattack on a computer system, application, or network designed to evaluate its security. It involves systematically probing for vulnerabilities that malicious attackers could exploit. The goal is to identify and address security gaps before they can be exploited by actual threats, ensuring the system’s robustness against cyberattacks.

The Purpose of Penetration Testing

The primary goals of penetration testing include:


  • Identifying Security Weaknesses: Pen testing helps organizations discover potential security gaps before malicious hackers can exploit them. By simulating real-world attack scenarios, security professionals can pinpoint specific vulnerabilities that might go unnoticed.


  • Assessing Risk Levels: Not all vulnerabilities are created equal. Penetration testing helps prioritize risks by demonstrating the potential impact of security breaches.


  • Validating Security Measures: Organizations can use pen testing to verify the effectiveness of their existing security controls, incident response procedures, and defensive mechanisms.


  • Compliance Requirements: Many industries have regulatory requirements that mandate regular security assessments, and penetration testing helps meet these compliance standards.

Types of Pen Testing

Penetration tests are categorized based on the scope and the information available to testers:


  1.  Black Box Testing: Testers have no prior knowledge of the system. This simulates an external attack by an uninformed hacker.


  2.  White Box Testing: Testers are given full information about the system, including architecture, source code, and configurations. This approach identifies vulnerabilities that may not appear in a black box test.


  3.  Gray Box Testing: A black-and-white box testing hybrid, where testers have partial knowledge. It mimics an attack from someone with limited insider knowledge.

Phases of Penetration Testing

A successful pen test involves several structured phases:


  • Planning and Information Gathering: During this initial phase, security professionals define the scope and objectives of the test. They carefully gather comprehensive information about the target system and identify potential entry points and vulnerabilities that might be exploited.

  • Scanning: In the scanning stage, automated tools are used to probe the system thoroughly. These tools help identify potential vulnerabilities by systematically examining the network and understanding how the target system responds to various intrusion attempts.

  • Exploitation: During this critical stage, testers attempt to exploit the discovered vulnerabilities using various sophisticated techniques. The goal is to demonstrate how an actual attacker might breach system defenses and gain unauthorized entry into the network or application or get into other malicious activities like data pollution, data destruction, data leakage, or denial of service.

  • Post-Exploitation: After successfully gaining initial access, penetration testers determine whether the discovered vulnerability can be used to establish persistent access. This stage simulates advanced persistent threat (APT) scenarios, helping organizations understand the potential long-term risks of a security breach.

  • Reporting: The final stage involves meticulously documenting all discovered vulnerabilities. Professionals provide detailed recommendations for remediation, carefully prioritizing risks based on their potential impact on the organization's security infrastructure.

Who Performs Penetration Testing?

Cybersecurity experts from different backgrounds carry out penetration testing. These include in-house security teams, specialized consulting firms, certified ethical hackers, freelance security researchers, and experts in specific domains. These professionals have high-level certifications like CEH (Certified Ethical Hacker) or OSCP (OffSec Certified Professional). They're skilled in networking, system architectures, coding, and security frameworks.


Pen testers, whether they work inside a company or as outside consultants, aim to do the same thing –they want to find and check possible weak spots in a company's digital setup. They do this through controlled, approved fake attacks. The best pen testers mix tech know-how with sharp thinking and strong ethics. They also know how to give useful tips to help companies beef up their cybersecurity defenses.

Penetration Testing vs. Vulnerability Assessment

Vulnerability Assessment and Penetration Testing are critical components of a robust cybersecurity strategy, but they approach security analysis from distinctly different perspectives.


  • Vulnerability Assessment: Vulnerability Assessment is a systematic and primarily automated cybersecurity process focused on comprehensively identifying and cataloging potential security weaknesses across an organization's IT infrastructure.

  • Pen Testing: Penetration Testing takes a more proactive and invasive approach to cybersecurity. Unlike Vulnerability Assessment, which passively detects vulnerabilities, Penetration Testing actively attempts to exploit identified vulnerabilities by simulating real-world cyberattack scenarios.

Conclusion

Pen testing plays a key role in a full cybersecurity plan. When companies take steps to find and address weak spots, they can reduce their chances of falling victim to cyberattacks. Regular and in-depth pen testing will remain crucial to maintaining strong security measures as online threats evolve.

Personal Identifiable Information (PII)

What is Personal Identifiable Information (PII)?

Personally identifiable information, or PII, is any type of information that can reveal who you are. This includes your full name, social security number, bank account number, email address, and phone number.

If someone can access this information, they can figure out your identity. For example, your social security number is unique, like your name and contact details. It's important to keep this information safe because if it falls into the wrong hands, someone could misuse it to pretend to be you or access your accounts.

Types of Personal Identifiable Information

Personal identifiable information comes in two forms, which includes:

  • Sensitive Personal Identifiable Information

Sensitive PII refers to information that could lead to serious issues if it falls into the wrong hands.. This might mean losing money, stealing your identity, or facing other major issues. Examples of sensitive PII are: 

– Your social security number

– Bank account numbers

Credit card details

– Health records

– Biometric data (like fingerprints or facial recognition data)


  • Non-Sensitive Personal Identifiable Information

Non-sensitive PII includes information that can identify you but is generally less harmful if someone else gets it. This type of information includes:

– Names

– Addresses

– Email addresses

– Phone numbers


Even though sharing this information might not lead to immediate serious problems, it can still be risky. For example, someone could use it to trick you into giving away more sensitive information through phishing attacks or social engineering. So, it's still important to be careful with this information to prevent misuse.

Security Impact on Personal Identifiable Information

Personal identifiable information can have serious consequences for both Individuals and businesses. For individuals, it can cause financial loss, identity theft, and privacy invasion. For businesses, poor security can result in losing customer trust, facing legal issues, and suffering financial losses. 


Organizations like businesses, hospitals and schools must keep this personal information secure to protect people's privacy. If there's a security breach and this information is exposed, it can cause long-term problems for individuals and their families.

Best practices to protect PII

Cybercriminals use tricks like phishing scams to steal personal information by pretending to be someone you trust. To prevent this, businesses should protect personal information by checking for stolen data that might be sold or shared illegally, training their staff, and promoting safe online practices to prevent unauthorized access and misuse of data.

Best Practices for Business

Businesses have a moral responsibility to protect people's privacy and personal information. As online crime increases, it’s becoming harder for companies to keep this information safe. However, there are steps businesses can take to reduce the risk to their customers.


Regular Security Training      

Businesses should prevent data breaches by teaching staff data privacy, and how to be safe and responsible online. It's important to train employees to raise awareness If anyone notices something suspicious, they should report it to the IT department right away. 


Data Encryption      

To keep sensitive information safe, businesses must make sure it is encrypted both when it’s being sent and when it’s stored. This helps prevent anyone from accessing it without permission.


Regular Security Audit

As an organization, you should regularly conduct security audits and risk assessments to identify and address any vulnerabilities. Additionally, ensure that anti-malware programs are installed on both individual computers and servers within your network to protect against threats.


Collaborate with Cybersecurity Companies 

If you don’t have a security response team to handle security incidents when they occur, you can collaborate with other verified agencies to ensure you receive expert assistance and effective solutions for addressing and resolving these issues.

Best Practices for Individuals

Protect Sensitive Documents with Passwords 

If you like keeping sensitive documents or information on your notepad or devices to help you remember them, it's important to set a password to protect that information from others.


Delete Sensitive information from Message Inbox

Do not share passwords or other sensitive information in your social media messages. If you need to use them, make sure to delete the messages afterward. Hackers who gain access to your accounts may have access to this information and cause more harm or steal from you.


Avoid Using Public Information for Security Questions

One common mistake people make is using information that is publicly available as their security question. Avoid using details that are easily found on your social media pages, work documents, or resume as your security question, because attackers can easily find this information and use it against you.

Client-Side Security

Client-side vulnerabilities and web page protection in JavaScript go hand-in-hand when the concern is client-side security. JavaScript security threats and risks are a real concern. Moreover, JavaScript may represent a security vulnerability for businesses when the source code is provided by third-party providers, for example.


  • First-Party JavaScript – The code an organization generates may have been secure when written. However, the code may have been tampered with after it went into production or reverse-engineered by malicious actors.

  • Third-Party JavaScript – JavaScript code originating from third-party sources poses a significant risk because it has all the same privileges as first-party JavaScript code. Since there are no default security settings for third-party JavaScript, the organization that operates the website or app pulling in that code is responsible for enforcing security and continuous monitoring.

  • Use of Forms and Secure Form Data – More than 90% of websites use forms to collect users’ personal information. Therefore, businesses must be committed to preventing breaches. On average, the personal information collected has a high level of exposure, involving more than 15 third-party domains, which increases the risk of unauthorized access to data and script misbehaviors.


Why do businesses need client-side security?

Client-side attacks have increased in cost and scale as companies expand their investments in the end-user digital experience. From Jscramblers’ experience, we give three fundamentals to start improvising the client-side security of your applications:


  • Identify all third-party JavaScripts running on your web applications and website;

  • Understand what these third-party JavaScripts are doing and why;

  • Define which scripts are allowed to access data in forms on payment pages and block those that should not.


Web applications typically load 20 or more third-party scripts as part of the digital user experience. By not developing a client-side security strategy and approach, security teams allow third-party code libraries to run amok on their servers.

The relevance of third-party scripts for users’ digital experience creates a JavaScript supply chain, and the lack of client-side security measures generates potential vulnerabilities to a software supply chain implemented almost in real-time on users’ devices. That said:


  • For businesses that accept online payments, users’ browsers may be facing a silent war.

  • Website forms are open windows for data breaches.

  • It is urgent to control third-party script behaviors on the client side, including tracking pixels and chatbots.

Phishing

How Phishing Works

Phishing attacks often begin with communication that mimics a legitimate source. This can be an email from what appears to be your bank, a message from a social media platform, or even a phone call. The goal is to trick the recipient into clicking on a malicious link, downloading harmful software, or directly sharing sensitive information.

For example, you might receive an email that looks like it's from your bank, warning you about "suspicious activity" on your account. The email contains a link that directs you to a fake website designed to capture your login credentials. Once you input your information, the attackers can use it to access your real account.

Common Phishing Tactics

  1. Email Phishing: The most common form of phishing, where attackers send emails that appear to come from legitimate organizations. These emails often include a call to action, such as asking you to verify your account, change your password, or confirm a payment. The email may contain a link to a fraudulent website that closely resembles the real one.

  2. Spear Phishing: Unlike general phishing attacks, spear phishing is highly targeted. Attackers gather personal information about the victim to craft a more convincing message. For example, they may impersonate a colleague, friend, or service you use, making the scam harder to detect.

  3. Smishing (SMS Phishing): In this variation, phishing attempts are made via text messages. You may receive an SMS asking you to click on a link to resolve an issue or claim a prize. Clicking the link often leads to a malicious site or downloads malware to your phone.

  4. Vishing (Voice Phishing): Vishing involves phishing attempts made through phone calls. Attackers may pose as representatives from your bank, government agencies, or even tech support, trying to extract personal or financial details.

  5. Clone Phishing: In this method, attackers create a near-identical copy of a legitimate email you previously received, altering the links or attachments to include malicious content. The attacker then resends the email, pretending it's an update or resend of the original message.

  6. Pharming: This involves redirecting users from legitimate websites to fraudulent ones without their knowledge. When users type the correct URL, they are unknowingly sent to a malicious website, where their personal information can be stolen.

Warning Signs of Phishing Attacks

Recognizing phishing attempts can be challenging, but there are common warning signs you should be aware of:


  1. Urgency: Phishing emails often create a sense of urgency, warning you that something needs immediate action, such as verifying your account or changing your password.

  2. Suspicious Links: Always hover over a link before clicking on it. If the URL looks unfamiliar or doesn’t match the legitimate site’s domain, it’s a red flag.

  3. Unusual Email Addresses: Check the sender's email address carefully. Often, attackers use addresses that look similar to legitimate ones but may contain small differences, such as extra numbers or letters.

  4. Spelling and Grammar Mistakes: Many phishing emails are poorly written, with spelling errors or awkward grammar. Legitimate companies usually have strict standards for communication, so mistakes are a sign of a potential scam.

  5. Unexpected Attachments: If you receive an unsolicited email with an attachment, be cautious. Opening attachments from unknown or suspicious sources can install malware on your device.

  6. Requests for Personal Information: Legitimate companies and organizations rarely ask for sensitive information like passwords, social security numbers, or credit card details via email or phone.

How to Protect Yourself from Phishing

  1. Be Skeptical of Unexpected Messages: If you receive an unexpected email, text, or phone call asking for personal information, take a step back. Verify the legitimacy of the request by contacting the organization directly through official channels.


  2. Use Two-Factor Authentication (2FA): Two-factor authentication adds an extra layer of security by requiring not just your password but also a second form of identification, such as a code sent to your phone. Even if attackers steal your credentials, 2FA can prevent them from accessing your account.

  3. Keep Software Updated: Regularly update your operating system, browsers, and other software to ensure you have the latest security patches. Cybercriminals often exploit vulnerabilities in outdated software.

  4. Use Anti-Phishing Software: Many antivirus programs include anti-phishing features that help detect malicious websites and prevent you from accidentally sharing your information.

  5. Educate Yourself and Others: One of the most effective ways to prevent phishing attacks is through awareness. Keep up to date with the latest phishing tactics and educate your friends, family, and colleagues on how to recognize them.

Conclusion

Phishing continues to be a prevalent cyber threat due to its ability to deceive people into revealing sensitive information. By staying vigilant, understanding the common tactics used by attackers, and employing best practices for online security, you can protect yourself from falling victim to phishing attacks.

Although technological solutions to some of the problems are feasible, the greatest safeguard rests with the user’s knowledge and prudence when handling unsolicited emails or unknown sites.

Payment Page Security

What is payment security?

Payment security encompasses the systems, processes, and measures that are implemented to safeguard payment card transactions against threats. These threats include unauthorized access, data breaches, and fraud.

In both online and offline transactions, prioritizing payment security is crucial for maintaining customer trust, minimizing financial losses, and a requirement to maintain compliance with relevant regulations and industry standards.

Payment security measures

Encryption

The payment page must use strong encryption protocols, like TLS (Transport Layer Security), to secure the data transmitted between the user's browser and the server. This encryption ensures that sensitive information, like payment card numbers and personal details, remains confidential and protected from unauthorized access during the data transfer.


Tokenization

If applicable, tokenization may be employed on the payment page. This involves replacing sensitive data (such as payment card numbers) with unique tokens. Even if these tokens are intercepted, they hold no intrinsic value or usable information.


Integrity

Techniques should be used to ensure the integrity of all JavaScript that executes on a Payment Page, whether the script originates from the merchant or a third-party. To minimize the attack surface, Payment Pages should restrict the amount of JavaScript on a page to the minimum necessary for business purposes.


PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) sets security standards for handling payment card information. Payment pages need to comply with these standards to ensure the secure processing, storage, and transmission of payment card data.


Authentication Measures

The payment page may invoke further authentication measures, such as 3D Secure, to verify the identity of the user and protect against unauthorized transactions. It is important to ensure that such authentication can not be intercepted for example by an overlay attack.


Secure Payment Gateway

The payment page typically interacts with a payment gateway, which facilitates the processing of the transaction. The payment gateway itself should be secure, employing encryption, tokenization, and other security measures to protect sensitive data.

Creating a Payment Security Strategy


Creating a strong payment security strategy includes conducting a thorough risk assessment, understanding compliance requirements, formulating security policies and procedures, deploying security measures, overseeing systems, adapting the approach as necessary, and formulating an incident response plan.

Periodic reviews are essential to ensure the effectiveness of the security strategy.

Payment Service Providers (PSPs)

Payment Service Providers

PSPs are third parties that enable merchants to accept electronic payment transactions – including credit and debit card payments, Direct Debits, bank transfers, and real-time bank transfers – by connecting them to the broader financial infrastructure. Examples include PayPal, Stripe, and Airwallex.

How do Payment Service Providers Facilitate Online Transactions?

PSPs provide merchants with access to a seamless payment gateway. This secure online portal connects their websites or applications to their payment processing system, facilitating the secure transmission of payment information to their customers and banks.

During this process, PSPs authorize, clear, and settle transactions. Having communicated with the customer’s bank or card issuer to verify their details and check for sufficient funds, they obtain authorization. This gives these intermediaries the go-ahead to execute the transfer of funds between the customer’s account and the business’s account.

Benefits of Using Payment Service Providers

PSPs offer several benefits for businesses that operate online or accept electronic payment transactions and the customers they serve:

 

Seamless integration

Intuitive APIs and integration tools allow businesses to start accepting payments on their e-commerce platforms, websites, and mobile apps expeditiously – eliminating the need to establish a dedicated merchant account and integrate a separate payment gateway.

 

Multiple payment methods

PSPs’ ability to accept different payment methods via a single platform simplifies the payment process, enhances the customer experience, and helps businesses stay competitive.

 

Faster transactions

PSPs provide the infrastructure, technology, and security measures necessary to facilitate instant transactions securely. This removes the friction associated with manual payment processing, allowing for faster transfers of funds.

 

Fraud protection

PSPs protect merchants and customers by implementing advanced client-side security features like authentication, encryption, tokenization, and monitoring for suspicious activity – a proactive approach to cybersecurity that prevents unauthorized transactions, improves cash flow management, and enhances customer satisfaction.

 

Compliance

PSPs must ensure their systems and processes comply with industry standards and regulations that govern data protection and fraud prevention, such as the Payment Card Industry Data Security Standard (PCI DSS). With sensitive payment data stored, processed, and transmitted securely, businesses achieve compliance and customer trust.

 

Global reach

PSPs allow businesses that operate across borders to accept payments in multiple currencies and settle transactions in their operating currency. This provides them with a platform to expand their reach, attract overseas customers, and tap into new markets.

 

Scalability

PSPs offer features that easily scale as businesses of all sizes grow. Whether they’re processing a few payments per day or handling a large volume, PSPs can handle fluctuating transaction volumes without significant infrastructure changes. This means businesses can use the same PSP as they grow without switching providers or establishing new payment processing arrangements.

 

What Does the Future Hold for Payment Service Providers?

With two-thirds of adults worldwide now using digital payments, it’s no surprise that they are set to more than double in value: the global digital payments market is projected to be worth $15.27 trillion by 2027, rising from $7.36 trillion in 2021. Amid this growth, PSPs will play a pivotal role in delivering fast, efficient, and secure digital payments on an eye-watering scale.

Client-Side Security

Client-side vulnerabilities and web page protection in JavaScript go hand-in-hand when the concern is client-side security. JavaScript security threats and risks are a real concern. Moreover, JavaScript may represent a security vulnerability for businesses when the source code is provided by third-party providers, for example.

 

  • First-Party JavaScript – The code an organization generates may have been secure when written. However, the code may have been tampered with after it went into production or reverse-engineered by malicious actors.
  • Third-Party JavaScript – JavaScript code originating from third-party sources poses a significant risk because it has all the same privileges as first-party JavaScript code. Since there are no default security settings for third-party JavaScript, the organization that operates the website or app pulling in that code is responsible for enforcing security and continuous monitoring.
  • Use of Forms and Secure Form Data – More than 90% of websites use forms to collect users’ personal information. Therefore, businesses must be committed to preventing breaches. On average, the personal information collected has a high level of exposure, involving more than 15 third-party domains, which increases the risk of unauthorized access to data and script misbehaviors.

Why do businesses need client-side security?

Client-side attacks have increased in cost and scale as companies expand their investments in the end-user digital experience. From Jscramblers’ experience, we give three fundamentals to start improvising the client-side security of your applications:

 

  • Identify all third-party JavaScripts running on your web applications and website;
  • Understand what these third-party JavaScripts are doing and why;
  • Define which scripts are allowed to access data in forms on payment pages and block those that should not.

Web applications typically load 20 or more third-party scripts as part of the digital user experience. By not developing a client-side security strategy and approach, security teams allow third-party code libraries to run amok on their servers.

 

 

The relevance of third-party scripts for users’ digital experience creates a JavaScript supply chain, and the lack of client-side security measures generates potential vulnerabilities to a software supply chain implemented almost in real-time on users’ devices. That said:

 

  • For businesses that accept online payments, users’ browsers may be facing a silent war.
  • Website forms are open windows for data breaches.
  • It is urgent to control third-party script behaviors on the client side, including tracking pixels and chatbots.

PCI DSS

What is PCI DSS?

The PCI DSS security standards were released in 2006 and have faced multiple revisions. The PCI DSS V4 version, the latest version, was released in March 2022 and will become effective in 2024.

The standard is divided into 12 principal requirements to achieve compliance. Each one contains multiple individual must-have items. Organizations must fulfill all of them to achieve PCI DSS certification.

There are around 240 requirements in total in a deep checklist to ensure compliance and secure payment data worldwide.

The 12 PCI DSS principal requirements

  1. Install and Maintain Network Security Controls;

  2. Apply Secure Configurations to All System Components;

  3. Protect Stored Account Data;

  4. Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks;

  5. Protect All Systems and Networks from Malicious software;

  6. Develop and Maintain Secure Systems and Software;

  7. Restrict Access to System Components and Cardholder Data by Business Need to Know;

  8. Identify Users and Authenticate Access to System Components;

  9. Restrict Physical Access to Cardholder Data;

  10. Log and Monitor All Access to System Components and Cardholder Data;

  11. Test Security of Systems and Networks Regularly;

  12. Support Information Security with Organizational Policies and Programs.

An organization can meet a requirement in one of two ways:

  • Way No. 1: The Defined Approach; and

  • Way No. 2: The Customized Approach.

When thinking about PCI DSS, separate two concepts:

  1. The written standard itself. It is a security standard, just like other security standards you may be familiar with, like ISO 27001 or the NIST Cybersecurity Framework.

  2. The card brand compliance programs. They require participants in their payment systems to comply with the standard.

PCI DSS Compliance: Defined Approach

The Defined Approach contains a prescriptive requirement and a prescriptive testing procedure.

The prescriptive requirement describes the controls the organization needs to implement to meet the requirement.

The testing procedure says what an assessor has to do to validate that the requirement is met. As an example, a defined approach requirement is:

The deployed anti-malware solution(s):

• Detects all known types of malware;

• Removes, blocks, or contains all known types of malware.

And the associated testing procedure:

Examine the vendor documentation and configurations of the anti-malware solution(s) to verify that the selected option:

• Detects all known types of malware;

• Removes, blocks, or contains all known types of malware.

PCI DSS Compliance: Customized Approach

The Customized Approach was introduced in version 4 of PCI DSS, allowing organizations flexibility to choose how they meet the requirement.

Rather than following the prescriptive controls contained in the defined approach, the organization can pick its controls to meet the Customized Approach Objective. For the example above, the Customized Approach Objective is:

Malware cannot execute or infect other system components.


To prove that an organization’s controls meet the objective, a rigorous assessment process is defined within the PCI DSS standard.

Compliance with PCI DSS

If an organization wants to participate in a card brand’s network to issue payment cards or acquire payment transactions made with those cards, it must sign a contract with the card brand. That contract will contain references to the card brand’s rules, which will specify that:

  • The organization has to comply with PCI DSS.

  • The organization has to confirm that all of their third-party service providers that can affect the security of cardholder data comply with PCI DSS.

  • If the organization acquires payment card transactions, the merchants that use the acquiring services must be PCI DSS-compliant.

Organizations are therefore required to comply with PCI DSS because of a contractual obligation:

  • The contract between a merchant or retailer and the acquiring bank will require the merchant to be compliant.

  • Contact between a financial institution that issues or accepts payment cards and a card brand will require the institution to be compliant.

  • Any contracts between merchants or financial institutions with third-party service providers who either store, process, or transmit cardholder data or who provide technology services that could affect the security of cardholder data will require the service provider to be compliant.

How to Demonstrate PCI Compliance

The card brand rules specify how an organization has to demonstrate its compliance with PCI DSS, and this will either be by undergoing an independent assessment or by completing a self-assessment.

The Independent Assessment:

It is an annual activity that validates the 240 PCI DSS requirements by following the testing procedures defined in the standard. It has to be carried out by either a Qualified Security Assessor (QSA) or an Internal Security Assessor (ISA).  

QSAs work for independent professional services companies; ISAs work for the organization being assessed but are independent of any function responsible for managing controls and are typically based in departments such as internal audits.

The PCI SSC provides training and accreditation to Both QSAs and ISAs.

The result of an independent assessment is documented in a Report on Compliance (RoC). This can be summarized in an Attestation of Compliance (AoC). The AoC is typically given to any entity that asks for evidence of compliance. Large merchants and service providers are required to have these formal assessments.

The Self-Assessment:

Smaller merchants and service providers will be asked to complete a Self-assessment Questionnaire (SAQ).

Someone inside the organization goes through the PCI requirements and marks the ones they comply with.

A few different SAQs are tailored to the different ways merchants accept payment transactions. Each one of these contains a subset of the appropriate PCI DSS requirements.

Sanctions and penalties for non-compliance

Historically, brands used to levy monetary penalties on ​​organizations that did not meet their contractual requirement to comply with PCI DSS. This does not happen now. However, it is still a sanction available within card brand rules.

When an organization suffers a breach of the confidentiality of cardholder data, it will be subject to sanctions by the card brands. They are required to engage a PCI Forensic Investigator (PFI), who will undertake an investigation to determine:

  1. The cause of the breach;

  2. Whether the breach has been rectified and the attacker removed from the network;

  3. Whether the organization was compliant with PCI DSS at the time of the breach; and

  4. Which elements of non-compliance were contributory factors to the breach?

For some card brands, any non-compliance with PCI DSS at the time of the breach can affect the amount of the penalty levied on the organization.

[LEARN MORE] Myth buster: 10 of the most common PCI DSS myths busted

Any organization that suffers a breach of cardholder data has to have assessor audits in the years following the leak until the card brand is happy that the organization is committed to following the PCI DSS standard.

PCI DSS v4

What is the purpose of PCI DSS?

The fundamental aim of PCI DSS is to safeguard and optimise the security of credit, debit, and cash card transactions and prevent cardholders’ personal information from being exploited, such as credit card numbers, expiration dates, and security codes.


Compliance with PCI DSS helps businesses minimise the risk of data breaches, fraud, and identity theft. It achieves this by providing a framework for adhering to industry best practices when processing, storing, and transmitting credit card data.


The PCI Security Standards Council created six major goals for PCI DSS:


  • Build and maintain a secure network and systems

  • Protect cardholder data

  • Maintain a vulnerability management programme

  • Implement strong access control measures

  • Regularly monitor and test networks

  • Maintain an information security policy

PCI DSS v4

In March 2022, the PCI DSS underwent its most significant update in almost four years with the release of version 4. In November 2023, the first minor revision, v4.0.1, was published. Following a transition period, the new requirements became effective on 1 April 2025.


The previous version, PCI DSS v3.2.1, was released in 2018. Since then, the cybersecurity landscape has undergone rapid evolution. 


The latest major iteration, PCI DSS v4, introduces notable changes in requirements, focusing on maintaining continuous security and implementing new methods to meet shifting requirements. This update aims to ensure the standard meets the evolving needs of the payment card industry and adapts to the new technologies being implemented on a daily basis.


PCI DSS v4 includes a raft of updates that aim to meet four key objectives:


  • Continue to meet the security needs of the payment industry

  • Promote security as a continuous process 

  • Add flexibility for different methodologies

  • Enhance validation methods


The implementation of a new method for meeting requirements, known as the customised approach, stands out. This instils the flexibility for organisations to comply with the security objectives of PCI DSS requirements using new technology and innovative controls. 

PCI DSS 4.0.1

Published in June 2024, the PCI DSS v4.0.1 update is a minor revision intended to clarify and correct the existing v standard. It neither introduces nor deletes requirements. It simply corrects formatting and typos and clarifies some requirements and guidance. This ensures a more accurate and consistent understanding and application of the existing version.


Implications for Organizations

These updates are designed to simplify the implementation of PCI DSS without increasing the compliance burden. If your organization is already aligned with v4, transitioning to v4.0.1 primarily involves reviewing clarified guidance and updating documentation. However, it's essential to reassess controls around patching, MFA, and legal exceptions to ensure alignment.

PCI DSS: the future

The future of PCI DSS will continue to be shaped by evolving cybersecurity threats, regulatory landscapes, and technological advancements in payment processing. As threats evolve, PCI DSS will continue to align with global standards and embrace innovations to safeguard payment data amid shifting priorities.

PCI DSS Requirement 6.4.3

PCI DSS Requirement 6.4.3


All payment page scripts that are loaded and executed in the consumer’s browser are managed as follows:


Authorization

A method is implemented to confirm that each script is authorized.


Integrity

A method is implemented to ensure the integrity of each script.


Inventory & Justification

An inventory of all scripts is maintained, with a written justification for why each is necessary.