Page 1 - GS191102
P. 1

November 25, 2019  •  Issue 19:11:02


                                     PCI SSC alive with



                          collaboration, innovation





                                                               learning and other advanced technologies can help pay-
                                                               ments industry stakeholders address increasingly complex
                                                               data environments," he stated.

                                                               Gary Glover, vice president of assessments at Security-
                                                               Metrics, said he and others on security's front lines were
                                                               warmly received at recent North American and European
                                                               community meetings. The PCI SSC is engaging earlier
                                                               and more frequently with stakeholders, which is helping
                                                               to make them feel more trusted as a community, Glover
                                                               added. For example, Payment Application Qualified Secu-
                                                               rity Assessors were shown a draft of the Strategic Software
                                                               Framework and asked to comment. And two comment and
                                                               draft review sessions are planned before the council pub-
                                                               lishes the PCI DSS 4.0 in late 2020 or early 2021.

                                                               This article shares further perspectives on these develop-
                                                               ments and other PCI SSC initiatives devised to increase in-
                                                               teraction, member engagement and innovation.
        By Dale S. Laszig
                                                               PCI SSC Strategic Framework
                 ecurity leaders found collaborative energy and
                 focus at the PCI Security Standards Council's  The Strategic Framework is designed to guide activities
                 2019 annual community meetings in North  and fulfill the council's mission to "enhance global pay-
        S America and Europe. In his European keynote,  ment account data security by developing standards and
        Lance Johnson, PCI SSC executive director, emphasized  supporting services that drive education, awareness and
        unity and said that in a rapidly changing environment,  effective implementation by stakeholders." The mission is
        "stakeholders can be certain that industry participation,  further defined by the strategic framework's four pillars,
        evolution, alignment and consistency will be constants in
        the council's efforts to provide standards and resources for
        securing payment data."
                                                                 Contributed articles inside by:
        Troy Leach, PCI SSC chief technology officer, agreed pay-
        ment  security  is  a  unifying  force,  even  for  competitive   Dee and Emily Karawadra .................................................................32
        council founders American Express, Discover, JCB, Mas-   Nicky Koopman .....................................................................................36
        tercard and Visa. In a September 2019 interview with The   Nicholas P. Cucci....................................................................................38
        Green Sheet, Leach said information sharing and technical
        competencies will continue to play a role in helping orga-  Hawkins Siemon ...................................................................................40
        nizations maintain compliance, protect data and defeat
        fraud. "Point-to-point encryption, tokenization, machine   TOC on page 3


                                                                                      Continued on page 30
   1   2   3   4   5   6