Lauren Holloway

speaker
57 appearances 1 recordings 1 series first heard Mar 2025 last heard Mar 2025

Lauren Holloway’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
Well, thank you, Alicia.
It's great to be with you today and to help clarify all this new information that the Council has released recently for our industry.
Well, there are 64 new requirements that were released in PCI DSS.
and 51 of them are future dated.
So the future dated requirements are effective, as Alicia said, on the 31st of March, 2025.
Requirements 643 and 1161 that she mentioned for e-commerce environments are part of these future dated requirements.
We received feedback that these requirements are challenging for many of our stakeholders, especially for smaller merchants, to implement them.
So we wanted to make sure we provided clarity and resources to assist them on their validation journey.
Now, the deadline to adopt these new requirements is a date that we've been talking about for three years.
PCI DSS version 4.0 was introduced in 2022.
and it became the only active version of the standard when PCI DSS version 3.2.1 was retired on the 31st of March, 2024.
The future data requirements have been in the standard since March of 2022 as best practices until the 31st of March, 2025.
After this 2025 date, these requirements are required and they must be fully considered during a PCI DSS assessment.
Well, in recent years, data breaches during e-commerce transactions, commonly known as e-skimming attacks, have increased significantly.
As e-commerce platforms have become more complex and businesses have grown more reliant on external scripts in their e-commerce environments, these attacks have become more common.
Scripts running in a consumer's browser are now a significant target for attackers seeking to steal payment card data.
So requirements 643 and 1161 were added to PCI DSS version 4.0 originally and now version 4.0.1 to reduce the risk of e-skimming attacks during e-commerce transactions.
These requirements focus on ensuring that payment page scripts are properly authorized, checked for integrity, and monitored for tampering, and to prevent unauthorized changes to web pages.
Yeah, Alicia, the objective of that task force was to develop guidance focusing on PCI DSS requirements 643 and 1161.
Specifically, they were tasked to produce a guidance document that provides clear and actionable guidance about how entities can meet these two requirements, guidance for how third-party service providers can help their customers to meet these requirements, and practical implementation strategies rather than a theoretical framework.
Showing 1–20 of 57 · page 1 of 3 Next →