Skip to the main content.
Contact
Contact

1 min read

PCI DSS Version 3.1 Has Arrived

PCI DSS Version 3.1 Has Arrived

The PCI Security Standards Council today published the expected update to PCI releasing these documents including some specific migration guidance:

Updates to the DSS Supporting documents like the ROC Reporting Instructions and to the PA-DSS Standard are expected to follow soon.

Some of the notable changes and guidance:

  • PCI DSS v3.0 will be retired June 30, 2015
  • All SSL and “early TLS” to be sunset by June 30, 2016 (see requirements 2.2.3, 2.3, 4.1)
  • Unacceptable secure session transport (all versions of SSL, TLS 1.0, and some implementations of TLS 1.1)
  • How to address SSL and early TLS in ASV scans
  • POS terminals and their receiving gateways can continue  to use SSL and early TLS after the sunset date provided it can be verified that the implementation is not susceptible to known exploits.
  • Clarifications on how to validate service providers and third party outsourcers
  • Added 3.4.e to ensure truncated and hashed PAN stored together cannot be used to reconstruct the original PAN
  • End-user protocols now includes the example of SMS (text messaging)
PCI Security Standards Council set to kill off SSL in PCI DSS/PA-DSS 3.1 updates

PCI Security Standards Council set to kill off SSL in PCI DSS/PA-DSS 3.1 updates

The PCI council has released an announcement that they are preparing an updated version of the PCI DSS (v3.1) and PA-DSS (v3.1), where they will be...

Read More
How a $1200 Graphics Card Threatens Your PCI DSS Compliance and Security

How a $1200 Graphics Card Threatens Your PCI DSS Compliance and Security

Organizations subject to PCI DSS compliance validation spend significant amounts of time, effort, and money to maintain and validate their...

Read More
NIST Moves on Sweet32 - 3DES, Blowfish, and Others - Mostly Unsafe

7 min read

NIST Moves on Sweet32 - 3DES, Blowfish, and Others - Mostly Unsafe

Now is the time to stop using 64-bit block length ciphers such as 3DES (TDEA) and Blowfish in general purpose applications of cryptography. In 2016,...

Read More