#pcidss40 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pcidss40, aggregated by home.social.
-
@jbhall56 wrote about PCI DSS 4.0 new Targeted Risk Analysis: https://pciguru.wordpress.com/2023/12/04/targeted-risk-analysis-guidance-provided/
To me targeted risk analysis sounds like a nice idea to let organizations focus more their risk analysis on their actual PCI DSS scope instead of trying to comply with more generic organization-wide risk analysis.
However, PCI DSS 4.0 seems to have interesting risk assessment design flaw unless I'm missing some requirement:
1) As old risk-assessment requirement is removed from 4.0 and new "TRA" risk assessment becomes effective in 2025, it seems to technically allow organizations to be PCI DSS v4 compliant without any risk assessment until 2025-03-31... whoops :-)
2) PCI DSS 4.0 allows skipping organizational / "more holistic" risk assessments which means that there is no need to analyse any risks / threats that are NOT related to requirements that PCI DSS 4.0 explicitly lists. This means that security risks and controls that go beyond PCI DSS set baseline does not need to be assessed technically. Nor actually any other PCI DSS requirements unless explicitly required to be under TRA assessment.
#pcidss #pcidss40 #riskassessment #designflaw #iamnotyourqsa