
[Recording] PCI 4 0 Addressing Client Side Security: A QSA Perspective
Digital skimming, formjacking, e-Skimming, Magecart – these are all methods used to steal credit card data and PII from transaction oriented websites. What should QSAs know?
In March 2022, the Payment Card Industry Security Standards Council released a revised version of its Data Security Standard, commonly known as PCI DSS v4.0. In this revised version are two new sections, 6.4.3 and 11.6.1 which offer guidance regarding 3rd, 4th, and nth party JavaScript running on your websites.
The articles, video and downloadable guide below are for anybody in the PCI DSS industry who focus on PCI DSS security and compliance and can be used as a resource for Qualified Security Assessors (QSA) who want to learn more about staying PCI compliant.
Digital skimming, formjacking, e-Skimming, Magecart – these are all methods used to steal credit card data and PII from transaction oriented websites. What should QSAs know?
The PCI Council made protecting data at the point of input a focus in PCI DSS 4.0. Sections 6.4.3 and 11.6.1 specifically call for preventative measures to close the security gaps that facilitate client-side attacks.
The shift online, with all of its benefits to businesses and consumers, also introduces serious risks to your business. As someone involved in the business side of digital, you need to understand these risks.
Digital skimming, formjacking, e-Skimming, Magecart – these are all methods used to steal credit card data and PII from transaction oriented websites. What should QSAs know?
We’re taking a closer look at PCI 11.6.1, what it entails, and how you can enhance your security strategy to meet this new guidance.
PCI 6.4.3 gives a nod to proprietary script management systems which have been created to specifically handle malicious script execution.
PCI’s latest guidance, 6.4.3 prompts security teams to prioritize managing and mitigating client-side web application attacks.
Every security practitioner responsible for a public-facing website that accepts payments should inform themselves thoroughly of the implications of this change.
These guidelines inform organizations of the necessity to make changes now. In this guide, we dive deep into PCI DSS v.4.0 and specifically:
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.