Webinar Replay: Last Minute Change to SAQ-A for QSAs
The PCI Security Standards Council has made a last minute, surprise update to SAQ-A eligibility requirements – changing scope for 6.4.3 and 11.6.1 just two months before the March 31st compliance deadline.Given on our role on the Ecommerce Guidance Taskforce, we have a ton of information to share, and we have unique insights given our pioneering position in eSkimming security. The TL:DR – while SAQ-A merchants no longer explicitly need to meet 6.4.3 and 11.6.1, they must still implement robust eSkimming protections to maintain SAQ-A eligibility.
CoalFire Provides Guidance on PCI DSS 6.4.3 and 11.6.1
Guidance from CoalFire on the eSkimming Security requirements found in PCI DSS 4.0.
The most talked about and concerning new requirements in PCI DSS 4.0 fall under sections 6.4.3 and 11.6.1. For the first time, merchants are required to implement security controls to prevent eSkimming attacks. These new requirements require control of all scripts running on merchant eCommerce websites.
In this new whitepaper “A Holistic Approach to Protecting Credit Card Payment Flows,” CoalFire chimes in with background on the problem, guidance on scope, advice on how best to secure credit card data in eCommerce transactions, and a review of the Source Defense approach.
Protect the trust behind every transaction.
Safeguard your digital supply chain and maintain unshakeable customer trust by shielding sensitive data from both inadvertent leakage and attacks from bad actors. Source Defense simplifies client-side security and data privacy while providing best-in-breed, enterprise-level protection.