Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: Get Ready for PCI 3.0 - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Get Ready for PCI 3.0

RIght on schedule (see their lifecycle doc at, the folks at PCI DSS have released a "what to expect" document for PCI 3.0.  I'm a bit late commenting on this - somehow I missed this when it was posted in August.  Specifically called out in the doc are:

  • Lack of education and awareness
  • Weak passwords, authentication
  • Third-party security challenge
  • Slow self-detection, malware
  • Inconsistency in assessments

The change document is here:

It'll be interesting to see what the final document will look like when it's released in November, and what happens when QSA's turn the PCI guidance into audit findings and recommendations.

Rob VandenBrink

Rob VandenBrink

577 Posts
ISC Handler
Sep 5th 2013

Sign Up for Free or Log In to start participating in the conversation!