usd at PCI Community Meetings in North America, Europe and Africa

23. October 2018

Representatives of usd AG attended the Middle East and Africa Forum in Cape Town in March and the PCI Community Meetings in Las Vegas and London in September and October of this year. At these meetings, experts of the Payment Card Industry gather to discuss current trends, innovations and best practices of the industry on an international level.

Anna-Magdalena Kohl, PCI Professional and usd Sales Representative, commented: “In terms of content, it was particularly evident that the industry is responding to technological innovations in the field of electronic transactions”.
The PCI Security Standards Council is currently developing new PCI standards for contactless payment methods on user devices, an updated version of the P2PE standard and a new software security framework as a further development of the PA-DSS. The next development stage of the PCI DSS is currently being prepared as well. A draft version has been announced for next year, which is scheduled to be finalized as PCI DSS v4.0 in 2020.

Christopher Kristes, Member of the Management Board and Head of Security Audits & PCI of usd AG, notes a growing trend towards more intensive cooperation: “Collaboration” was a major topic this year. In the future, the Council will focus even more on the community. Within the framework of the PCI PIN, for example, the Council works closely with the standardization organization ASC X9. The PCI SSC Global Executive Assessor Roundtable (GEAR), to which we have been appointed as a member, is another wonderful example of this. With the GEAR, the PCI SSC took a step to promote direct communication and exchange with the assessor community. We were delighted to share our experiences with this important group for the first time in September this year”.

Also interesting:

Security Advisories on OrangeHRM und memos

Security Advisories on OrangeHRM und memos

The pentest professionals at usd HeroLab identified multiple vulnerabilities in the applications OrangeHRM and memos during web application pentests. The vulnerabilities were reported to the vendors as part of the Responsible Disclosure Policy. Detailed information on...

DORA Deep Dive: Threat-Led Penetration Testing (TLPT)

DORA Deep Dive: Threat-Led Penetration Testing (TLPT)

Since the publication of the original blog post in May 2024, the final version of the RTS for TLPT has been released. The blog post has been updated accordingly and now covers the current requirements. The Digital Operational Resilience Act (DORA) came into force on...

Categories

Categories