The new version of PCI due out in October will let the outdated WEP wireless security standard stick around for almost two more years, while also reducing the required frequency of firewall rule reviews.
But the changes confirmed by the PCI Security Standards Council this week—which have been circulated among members for the last few weeks—provide few other substantive changes, delivering the mild tweaks and updates the council has publicly promised.
The document lists some 30 changes to the current PCI Version 1.1 and PCI officials promise that the official and final version—now slated for release on Oct. 1, a few weeks earlier than originally expected—will include yet more changes.
Still, the document provides a fairly detailed peek into the council's thinking. The most significant change is language that addresses the much-maligned WEP and tried to balance conflicting member interests, from those who argued that such a weak security approach should be banned as soon as possible and their opposite numbers, who spoke to the cost and effort that retailers would need to deploy to make the change.Read more...