



























The PCI Security Standards Council (PCI SSC) has released a new information supplement, PCI DSS v4.x: Guidance for Compensating Controls and the Customized Approach. The document provides practical guidance to help assessed entities and assessors navigate two options in PCI DSS v4.x that provide flexibility but are often misunderstood – the use of compensating controls and the customized approach. PCI SSC developed this guidance in collaboration with industry stakeholders, including the Global Executive Assessor Roundtable (GEAR) and the Board of Advisors (BOA).
PCI DSS v4.x offers organizations two paths to implement and validate PCI DSS requirements: the defined approach and the customized approach. These two approaches have different intents, elements, documentation, and validation. Compensating controls, an option within the defined approach, serve a different purpose from the customized approach. Unlike compensating controls, which are used when organizations have a technical or business constraint and are unable to meet the requirement as stated, the customized approach is for entities that choose to meet the requirement differently than is stated.
Highlights Include:
The new guidance document addresses the roles of both assessed entities and assessors, and provides references and supporting materials, including an Appendix with a variety of completed examples of compensating control and customized approach templates.
Organizations undergoing PCI DSS assessments should review this information supplement, which is now available in the PCI SSC Document Library. Entities planning to use either approach should work with the organization(s) that manages their compliance program, such as an acquirer (merchant bank), payment brand, or other entity, to understand the entity's compliance validation and reporting responsibilities.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。