ANALYST REPORT

OBS Verifies Jscrambler Iframe Integrity Prevents Payment Page Script Attacks

In response to PCI DSS v4.0.1, merchants must ensure their payment pages are protected against skimming attacks. With Jscrambler’s recently launched Iframe Integrity, PSPs are now empowered to armor payment page iframes and protect merchant payment pages from skimming attacks while meeting PCI DSS compliance.

This whitepaper covers an in-depth assessment by OBS of Iframe Integrity, verifying its protection capabilities and ability to enable PCI DSS compliance.

Navigating PCI DSS Anti-Skimming Requirements and Jscrambler’s Iframe Integrity Solution

The Challenge: Anti-Skimming Added To PCI DSS

New anti-skimming requirements in PCI DSS 4.0.1 are raising the bar for e-commerce security, aiming to protect payment pages and parent pages from increasingly
sophisticated script-based attacks.

The Solution: Iframe Integrity Evaluation

Iframe Integrity is a multilayered offering that helps PSPs achieve PCI DSS compliance (for requirements 6.4.3 and 11.6.1) and simplifies SAQ A eligibility for PSPs’ merchant clients.

The Conclusion from OBS

Deploying the solution to a merchant’s parent page, as part of a PSP’s payment page script, appears to be a successful way of ensuring that the merchant’s payment page is not susceptible to script attacks.

“Iframe Integrity was successful in preventing all the tested attacks. Deploying the solution to a merchant’s parent page, as part of a PSP’s payment page script, appears to be a successful way of ensuring that the merchant’s payment page is not susceptible to script attacks.”

OBS

Related Resources