4 days ago

PCI DSS Periodic Activities

In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic requirements within the Payment Card Industry Data Security Standard (PCI DSS).  Alastair and Tibor leverage nearly 30 years’ combined experience with the PCI DSS to discuss:  

  • Why PCI DSS v4 moved away from fixed frequencies and towards risk-based intervals for some controls
  • The common mistakes they see organisations make when defining their own frequencies
  • Whether the introduction of Requirement 12.3.1 has improved security outcomes or simply increased documentation requirements
  • How PCI DSS targeted risk analysis (TRA) differs from an enterprise risk assessment and why organisations frequently confuse the two
  • How to determine appropriate activity frequency and the evidence that shows QSAs an organisation’s chosen frequency is reasonable
  • How to meet specific requirements such as Periodic Evaluation of Systems Not Considered at Risk from Malware, Application and System Account Reviews, and Change and Tamper Detection Mechanisms
  • And more.

Ask Alastair and Tibor a question: https://urmconsulting.com/podcasts/pci-dss-periodic-activities

 

If you enjoyed this episode of InfoSec Insider, you can leave us a rating and review here:  https://ratethispodcast.com/infosecinsider         

 

You can find more episodes of InfoSec Insider here:  https://urmconsulting.com/podcasts         

 

 Connect with us on LinkedIn 

 

Brought to you by URM, the UK’s leading information and cyber security specialists.   

Comment (0)

No comments yet. Be the first to say something!

Copyright 2026 URM Consulting. All rights reserved.

Podcast Powered By Podbean

Version: 20241125