ARTICLE
11 March 2015

PCI Security Standards Council Announces Revisions To The Use Of SSL

RS
Reed Smith (Worldwide)

Contributor

Reed Smith (Worldwide) logo
Reed Smith is a dynamic international law firm helping clients move their businesses forward. By delivering smart, creative legal services, we enrich clients' experiences with us and support achievement of their business goals. Our longstanding relationships and collaborative structure enable the speedy resolution of complex disputes, transactions, and regulatory matters.
These impending revisions should help organisations in protecting their data and dealing with processing payment card information.
United Kingdom Privacy

The Payment Card Industry (PCI) Security Standards Council has released a bulletin on impending revisions to version 3.0 Payment Application Data Security Standards (PA-DSS) and version 3.0 of the PCI Data Security Standard (PCI-DSS), which we reported on in January 2014.

To ensure the continued protection of consumers' payment data, the PCI Security Standards Council has changes that align with National Institute of Standards and Technology's findings that Secure Socket Layers (SSL) v3.0 is no longer adequate because of inherent weaknesses within the protocol.

The findings mean that no version of SSL meets PCI Security Standards Council's definition of "strong cryptography". As a result, new revised standards PCI-DSS v3.1 and PA-DSS v3.1 will be published to reflect the findings.

The bulletin states that these revised standards will be "effective immediately, but impacted requirements will be future dated to allow organisations to implement the changes". In the interim, organisations are encouraged to find out whether they are using SSL and, if so, to upgrade to a "strong cryptographic protocol as soon as possible".

These impending revisions should help organisations in protecting their data and dealing with processing payment card information.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More