Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Audits

PCI SSC Releases New Security Standards for Payment Software

The Payment Card Industry Security Standards Council (PCI SSC) this week announced new security standards for the design, development and maintenance of payment software.

The Payment Card Industry Security Standards Council (PCI SSC) this week announced new security standards for the design, development and maintenance of payment software.

The new PCI Secure Software Standard and the PCI Secure Lifecycle (SLC) Standard are part of a new Software Security Framework and their goal is to ensure that the development of payment software keeps up with modern practices.

The PCI Software Security Framework includes assessment and validation programs, which are expected to become available sometime this year.PCI SSC releases new software security standards

The PCI Secure Software Standard summarizes the security requirements and assessment procedures for ensuring that payment software properly protects transactions and data. The standard focuses on secure default configurations, identification of critical assets, protection of sensitive data, access control and authentication, threat detection, and security guidance for vendors.

The standard is similar to the Payment Application Data Security Standard (PA-DSS) and the plan is to retire the PA-DSS over the next few years while a gradual transition is made towards the new standard.

PCI SSC hopes that this new standard will be used not only by organizations that sell, distribute or license payment software, but also by organizations that use and develop these types of tools internally.

The PCI Secure SLC Standard is meant to ensure that good security is maintained when changes are made to an application. Its key principles include vulnerability detection and mitigation, governance, security testing, threat detection, secure software updates, change management, and stakeholder communications.

This standard has been designed for software vendors that offer their products to the payment industry.

The new standards have been developed based on feedback from hundreds of software vendors, assessors and payment security experts, the PCI SSC said.

Advertisement. Scroll to continue reading.

“Software development practices have evolved over time, and the new standards address these changes with an alternative approach for assessing software security,” said PCI SSC Chief Technology Officer Troy Leach. “The PCI Software Security Framework introduces objective-focused security practices that can support both existing ways to demonstrate good application security and a variety of newer payment platforms and development practices.”

Related: What You Need to Know About PCI DSS Compliance this Holiday Season

Related: Wi-Fi Alliance Launches WPA3 Security Standard

Related: UK Publishes Minimum Cyber Security Standard for Government Departments

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.