
4 days ago
PCI DSS Periodic Activities
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS). Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:
- Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
- The common mistakes they see organisations make when defining their own frequencies
- Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
- How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
- How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
- How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
- And more.
Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities
If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Connect with us on LinkedIn
Brought to you by URM, the UK’s leading information and cyber security specialists.
No comments yet. Be the first to say something!