Low Guidance global

PCI SSC publishes Guidance for Compensating Controls and the Customized Approach Sub

Original title: Guidance for Compensating Controls and the Customized Approach Sub

PCI Security Standards Council has published new guidance for compensating controls and the customized approach. This guidance provides organizations with frameworks and best practices for implementing alternative controls when standard requirements cannot be met, and for tailoring their compliance approach based on their specific business context. It supports organizations in maintaining security while adapting PCI DSS requirements to their operational environments.

What changed

  • PCI SSC publishes new guidance document titled "Guidance for Compensating Controls and the Customized Approach Sub" to clarify how organizations can implement compensating controls when standard PCI DSS requirements are not feasible.
  • Guidance outlines the customized approach methodology, enabling organizations to tailor PCI DSS compliance strategies to their specific business needs and operational constraints.
  • Framework provides criteria and best practices for evaluating and implementing compensating controls that maintain the security intent of the standard while accommodating legitimate operational limitations.

Who is affected

Organizations subject to PCI DSS compliance globally, including payment processors, merchants, service providers, and other entities handling payment card data who seek to implement compensating controls or customize their compliance approach.

Language
EN

Frameworks

PCI DSS

Open the original source