Tuesday, January 31, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

PCI DSS compliance improving but still lags highs

Researcher by Researcher
September 11, 2022
in Cybersecurity
0
PCI DSS compliance improving but still lags highs
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The new PCI DSS 4.0 standard means organizations will have to up their game beginning in 2024.

Business, technology, internet and networking concept. Young businesswoman working on his laptop in the office, select the icon security on the virtual display.
Image: Adobe Stock

While compliance with the PCI Data Security Standard has improved significantly in 2020, it is still well off its 2016 highs, according to the 10th 2022 Verizon Payment Security Report.

Data security compliance has improved, but a new standard will push organizations further

Must-read security coverage

“Following three years of full compliance in decline (2017 to 2019), organizations focused their attention on improving security management and governance, resulting in significant gains across six of the 12 Key Requirements [of the PCI DSS standard],” the report said.

In response to ever escalating cyberthreats in the payments industry, the PCI Security Standards Council instituted its most ambitious rewrite of the PCI DSS since 2004, the report said. Released earlier this year, PCI DSS version 4.0 will go into effect in 2024.

“The latest update will help organizations ensure that data security controls remain relevant and effective in a shifting landscape,” the report said.

Aside from detailing changes in PCI DSS compliance, the report also lays out a roadmap for organizations implementing version 4.0 of the PCI DSS standards.

“Since the release of PCI DSS v1.0 in 2004, most organizations continue to struggle with achieving and maintaining effective, sustainable payment card data security,” the report said. “Those that succeed in maintaining all their PCI DSS requirements year-round—rather than ongoing remediation for the sake of passing an annual assessment—implement a strategy and design based on sustainable, well-developed goals.”

SEE: Mobile device security policy (TechRepublic Premium)

How organizations are maintaining data security compliance

The 2022 PSR found that overall PCI DSS compliance improved significantly in 2020, with 43.4% of organizations maintaining full compliance, a 15.5% improvement over the record low of 27.9% in 2019. But these numbers are well off the all time highs achieved in 2016 when 55.4% of organizations reported to be in full compliance.

Even though 57% of organizations failed their interim validation assessment due missing security controls, the security control gap improved from 7.7% in 2019 to a 4.0% in 2020. The control gap is the difference between the measured state of compliance vs. having 100% of required controls in place, the report said. A low gap number is good and a high gap number is bad.

The report also noted a significant increase in the use of compensating controls, with 30.1% of organizations across the globe applying one or more compensating controls—a 5.4% increase from 24.7% in 2019. A compensating control is used when organizations are unable to meet a key requirement as stated in PCI DSS.

The key requirements organizations meet most consistently continue to be restricting access to data, protecting data in transit, protecting the network against malicious software and controlling physical access. Over 80% of organizations meet these key requirements, the report said.

These are followed by protecting stored cardholder data, authenticating access and maintaining firewalls. These key requirements are met by just 70% of organizations.

The worst-performing requirements continue to be regularly testing security systems and developing and maintaining secure systems. Fewer than 70% of organizations maintain these requirements, the report said.

Additional report findings highlight improvements in security testing, with 60.1% or organizations in 2020 vs. 51.9% in 2019 successfully testing security systems, processes and unmonitored system access.

“Despite compliance improvements, we know that bad actors are still out there and stronger than ever,” said Ciske Van Oosten, Head of Global Business Intelligence, Verizon Cyber Security Consulting, in a press release.

SEE: Password breach: Why pop culture and passwords don’t mix (free PDF) (TechRepublic)

About the report

The Verizon 2022 PSR report is based on the analysis of quantitative data gathered by QSAs from multiple Qualified Security Assessor Company (QSAC) organizations across the world. The dataset for this edition is based on information from five sources, four of them external to Verizon.



Source link

Related articles

Novel Malware Installed in VMware ESXi Attacks

VMware Fixes vRealize Log Insight RCE Bugs

January 31, 2023
Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

January 30, 2023
Tags: complianceDSSHighsImprovinglagsPCI
Share76Tweet47

Related Posts

Novel Malware Installed in VMware ESXi Attacks

VMware Fixes vRealize Log Insight RCE Bugs

January 31, 2023
0

VMware has released updates for a group of four vulnerabilities in its vRealize Log Insight logging platform, three of which...

Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

January 30, 2023
0

There are many organizations moving to the cloud every day. Some are developing software at a fast pace, some are...

The Effect of Cybersecurity Layoffs on Cybersecurity Recruitment

The Effect of Cybersecurity Layoffs on Cybersecurity Recruitment

January 30, 2023
0

On Friday, January 20, 2023, Google announced it would lay off 12,000 employees. Amazon and Microsoft have laid off a...

How IT Budgets Should Fill Cybersecurity Moats in 2023

How IT Budgets Should Fill Cybersecurity Moats in 2023

January 30, 2023
0

TechRepublic speaks with Carlos Morales of Neustar Security Services on the best ways for companies to spend on cybersecurity —...

Boosting Data Security with AI and Blockchain | by Binu Panicker | Jan, 2023

Boosting Data Security with AI and Blockchain | by Binu Panicker | Jan, 2023

January 30, 2023
0

Today, data is considered the new oil and rightly so because the amount and type of data collected on people...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Novel Malware Installed in VMware ESXi Attacks

VMware Fixes vRealize Log Insight RCE Bugs

January 31, 2023
KITMEK Launches $1 Digital Only School for Children Across MENA

KITMEK Launches $1 Digital Only School for Children Across MENA

January 31, 2023
Whole-Network Visualization With Meraki Dashboard

Whole-Network Visualization With Meraki Dashboard

January 31, 2023
Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

Securing CI/CD. There are many organizations moving to… | by Binu Panicker | Jan, 2023

January 30, 2023

Recent Posts

Novel Malware Installed in VMware ESXi Attacks

VMware Fixes vRealize Log Insight RCE Bugs

January 31, 2023
KITMEK Launches $1 Digital Only School for Children Across MENA

KITMEK Launches $1 Digital Only School for Children Across MENA

January 31, 2023
Whole-Network Visualization With Meraki Dashboard

Whole-Network Visualization With Meraki Dashboard

January 31, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Finds Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved