Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    PCI DSS Dials Back on SSL/TLS 1.1 Requirement

    Written by

    Sean Michael Kerner
    Published December 22, 2015
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Organizations that need to be compliant with Payment Card Industry Data Security Standard (PCI DSS) version 3.1 are getting a reprieve on a key compliance measure. They now do not need to migrate to Transport Layer Security (TLS) version 1.1 or higher until June 2018, a two-year delay from the original data of June 2016.

      The PCI DSS 3.1 standard first debuted in April, shifting away from older versions of TLS and Secure Sockets Layer (SSL) in a bid to reduce the risk of exposure from insecure data transport protocols. One of the key requirements in PCI DSS 3.1 is for organizations to disable all use of SSL version 3. SSL has been determined to be cryptographically insecure by a large volume of research, as evidenced by the POODLE vulnerability in SSL 3 that was first disclosed in October 2014.

      “One of the key factors that gave us the confidence in pushing out the date to June 2018 is that, at the moment, we’re not seeing criminals accessing cardholder data through these vulnerabilities,” Jeremy King, international director of the PCI Security Standards Council (PCI SSC), told eWEEK.

      In moving the date back, PCI SSC is trying to balance risk and operational needs, King said. That is, how does the risk associated with the added time needed to migrate to TLS 1.1 or higher balance with the potential loss of business for merchants, processors and assessors?

      “What is absolutely clear is that this is not a signal to organizations to do nothing for two years. In fact, it is quite the opposite,” he said. “For sure, if a company can migrate away from SSL and early TLS today, then they should do so immediately.”

      If it is not practical for an organization to move to TLS 1.1 or higher just yet, then the company must understand that it is at greater risk and so must take greater care, King stressed. Organizations must have clear mitigation and migration plans to deal with the time between now and their migration, and they must be very aware of strange activity related to SSL and early TLS protocols.

      As to why PCI SSC is making the announcement about the TLS migration date now, during the busiest time of the year for retailers, King said the announcement is being made as early as possible after receiving and analyzing feedback from the PCI SSC’s global community.

      “After merchants and service providers started looking at their systems to make the shift, it became apparent to them that the migration was going to have far wider-ranging business implications than was originally thought,” he said. “This made the original shift date challenging for virtually everyone.”

      David Picotte, manager of security engineering at Rapid7, is among those who are not surprised at PCI SSC’s extension of the TLS migration deadline. Picotte said PCI SSC doesn’t want the majority of merchants suddenly assessing PCI DSS in a noncompliant state because time ran out.

      “It’s also possible that the date gets moved forward should a new attack technique be discovered in the coming years that dramatically reduces the complexity of a successful attack,” Picotte told eWEEK. “To remain secure, merchants should ensure that all new implementations use TLS 1.1 or above.”

      Rob Sadowski, director of marketing at RSA, the Security Division of EMC, said there is no question that the migration away from SSL and early TLS is absolutely necessary to protect payment data and other sensitive data types. Extending the migration deadline is a pragmatic concession by PCI SSC that some legacy hardware environments will be very difficult to patch or update, he added.

      “Some of the most vulnerable environments, such as e-commerce, have already migrated or efforts should be well underway,” Sadowski told eWEEK. “Despite the extension, organizations that are affected are generally aware that they should not be waiting another two years to address this well-known vulnerability.”

      From a PCI DSS standard perspective, a formal update set to be released in 2016 that will codify the migration date move as well as provide additional changes to PCI DSS. King said 2016 is already scheduled to be a PCI DSS standard update year, as per the PCI SCC’s standards development life cycle. It’s not clear yet if the 2016 update will still be called PCI DSS 3.1 or if it will be given a new number.

      “We are conscious that too many changes in quick succession can cause confusion to the marketplace, so we are currently looking at how best to proceed,” King said. “Therefore, the version iteration has not yet been finalized. As soon as it is, we will let everyone know.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.