
PCI DSS 4.0 Released with Big Changes
Released March 31, 2022, PCI DSS v4.0 contains significant changes including increased focus on risk analysis, which may open organizations up to legal risks.
The last year has seen an increase in data breach and hacking activities, along with the proliferation of ransomware attacks. That’s why one of the key priorities for companies in 2019 is to have a data protection plan in place.
A strong data protection program can minimize the impact of cyber-attacks on business operations, protect customer data, and help spare companies from legal liabilities, public embarrassment, and missed customer expectations.
Data protection covers the confidentiality, integrity, and availability of data stored or processed by a business.
Implementing controls for confidentiality helps ensures that data remains private. To maintain privacy, appropriate security safeguards are deployed to allow only those with authorized access to view or edit data. Common methods for providing data protection for confidentiality include:
Data protection for integrity ensures the accuracy and consistency of data through its lifecycle within a company’s systems and helps prevent the corruption or deletion of data. Strategies for maintaining data integrity include ensuring audit trails are maintained and data backups are regularly executed.
Most compliance and regulatory standards have provided additional guidance for data protection for availability, particularly because of the threats that ransomware poses. Tactics include:
In recent years, greater emphasis has been placed on data protection strategies for companies operating in regulated spaces. Companies must understand the data protection requirements they’re required to meet in order to comply with various standards or regulations such as:
In summary, a well-developed data protection strategy should address the confidentiality, integrity, and availability of data. Incorporating best practices for security and data protection can also meet many compliance requirements.
Data protection starts with understanding your data assets and where they are housed. Ensuring timely patching and vulnerability scanning is important, as is developing a tiered recovery plan to protect the data. Layering backup services, replication, and disaster recovery as a service (DRaaS) can help meet the data protection requirements outlined in standards such as PCI-DSS or HIPAA. If your company doesn’t have expertise in the data protection space, a trusted partner can augment your IT services or provide guidance to help you meet your compliance obligations.
For more information about data protection and compliance for 2019, contact US Signal. Call 866.2. SIGNAL or email us at: [email protected].
Released March 31, 2022, PCI DSS v4.0 contains significant changes including increased focus on risk analysis, which may open organizations up to legal risks.
When an organization works with US Signal, both entities work together to determine who will be responsible for the security of each aspect of the IT infrastructure solution. This includes defining and fully describing what is entailed for each responsibility; discussing the arrangements to ensure complete understanding; [...]
The US Signal approach to IT security entails joint responsibility, regularly tested processes and protocols, and the benefits of a private network.