Lauren Holloway
speaker
57 appearances
1 recordings
1 series
first heard Mar 2025
last heard Mar 2025
Lauren Holloway’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
Now, this new guidance document was released last week.
It's got kind of a long name.
It's called Payment Page Security and Preventing E-Skimming Guidance for PCSS Requirements 643 and 1161.
This document is intended for any entity that processes payment card transactions through e-commerce via embedded iframes or with a webpage that can impact security of e-commerce payments.
The information supplement provides specific guidance for merchants and third-party service providers working to meet PCA DSS requirements 643 and 1161.
Before I go into that, it's important to remember that SAQA includes only the PCI DSS requirements that are applicable to merchants with account data functions completely outsourced to PCI DSS compliant third parties, where the merchant is retaining only paper reports or receipts with account data.
And SAQA merchants are either e-commerce merchants or they may be mail order, telephone order merchants.
Basically, they're all card not present merchants.
And these merchants don't store, process, or transmit any account data in electronic form on their systems or premises.
So the changes we made to SIQ recently were to remove these two-piece IDSS requirements, 643 and 1161, for payment-paid security.
And we also removed requirement 1231 for a targeted risk analysis because this targeted risk analysis was only there to support requirement 1161.
We also added an eligibility criteria for merchants to confirm that their site is not susceptible to attacks from scripts that could affect the merchant's e-commerce systems.
Now regarding this new eligibility criteria, we received a lot of questions about that eligibility criteria and we recently produced an FAQ that Alicia mentioned to help clarify exactly what that eligibility criteria means.
and how a merchant can confirm that their website is not susceptible to script-based attacks that could compromise the merchant's e-commerce systems.
So in the FAQ, we clarify that merchants can confirm this either by using techniques such as, but not limited to, those that are spelled out in PCI DSS requirements 643 and 1161 to protect the merchant's webpage from scripts targeting account data.
Now, these techniques may be deployed by the merchant or they could be deployed by a third party.
Alternatively, the merchant can obtain confirmation from the merchant's PCI DSS compliant third party service provider or payment processor that is providing the embedded iframe.
And this confirmation would be when implemented according to the third party's instructions, the third party's solution includes techniques that protect the merchant's payment page from Scripps attacks.
We also clarified that a provider of third party Scripps is not considered a third party service provider or TPSP for purposes of SAQA.
if the provider's only service is providing scripts that are not related to payment processing and where those scripts cannot impact the security of payment account data.
Showing 21–40 of 57 · page 2 of 3
← Previous
Next →