The PCI SSC released the final versions of the PCI DSS v3 and PA-DSS v3 this morning. You can get your copies here as long as you sign their agreement. The Change Summary documents for both are also finalized and available in the library. Enjoy!
07
Nov
13
Very subtle change to the Scope of PCI DSS Requirements “Systems that provide security services (for example, authentication servers), facilitate segmentation (for example, internal firewalls), or may impact the security of (for example, name resolution or web redirection servers) the CDE.”
What impact will including “web redirection servers” have on merchants using hosted payment gateways, previously a strategy for de-scoping?
It means that those merchants will have to monitor and secure the servers that do the re-direct. It’s not huge, but they are in scope.