How has the PCI Data Security Standard changed (January 2005 version to version 1.1)?
The focus of the 1.1 revision has been to address questions about how to implement the standard. The standard has been updated to provide clarification to certain requirements and to give flexibility for compensating controls for complex requirements such as data encryption. These updates are designed to acknowledge partner and customer feedback, along with technical compliance constraints, and foster rapid adoption, while maintaining the robustness of the security measures in the January 2005 version. Additional requirements have been added to address emerging threats related to application security.
Related Questions
- If I am already PCI DSS compliant based on the January 2005 version of the PCI Data Security Standard and have initiated the re-certification process, what impact will version 1.1 have?
- When will the new version of the PCI Data Security Standard (version 1.1) become effective?
- How has the PCI Data Security Standard changed (January 2005 version to version 1.1)?