In a brief yet bold announcement, the PCI Security Standards Council today announced that the card brands have come to an impasse and cannot agree on key provisions of PCI DSS v4.
Council Communications Director, April Fools-Day, states in the Councilâs Blog post that, âThe card brands have tried and tried to work through their differences on key parts of the new version of the PCI DSS, but their differences have been unable to be resolved. As a result, the Council has been informed that we will need to go back to pre-Council times when each card brand had their own security compliance program.â
An anonymous source from American Express stated that, âWe fully expect to have our security program issued in a matter of days. We were happy with where version 4 was headed, and we intend to publish that program with only minor revisions.â
A source from Visa USA who insisted on anonymity because they are not allowed to officially speak about the matter stated, âVersion 4 as it existed was not an advancement. Too many loopholes in the work program. It wasnât about to advance security of card data and was taking us back to the dark ages of information security.â
A Mastercard spokesperson stated, âWhat Visa said.â
Spokespeople for Discover and JCB had no comment on the news.
Dr. Brandon Williams, a known critic of the Council stated, âIt was just a matter of time before this all imploded. I have seen this coming for years.â
Dr. Anton Chuvakin, noted SIEM expert and author of many PCI DSS books, said, âMeh!â
The PCI Dream Team were stunned by the news. However, after a moment to catch his breath, Art âCoopâ Cooper said, âI suppose it was bound to happen at some point. I just thought it would be decades out.â
It will be interesting to see the reaction to this news as people let it all sink in. In the meantime, enjoy April the First.