Decrypt PCI DSS 4.0 Special with John Hetherton
Blog post from Evervault
In this episode of Decrypt, Shane and John Hetherton, Head of Compliance at Evervault, discuss the transition from PCI DSS v3.2.1 to the more robust v4.0 and its implications for organizations handling online payments. The conversation highlights the key differences between the two versions, notably the shift to an outcome-based approach that allows organizations to customize their compliance measures, provided they meet the intended security outcomes. John shares his journey into cybersecurity, emphasizing the importance of understanding and adapting to evolving standards, and outlines Evervault's proactive steps in achieving early compliance with v4.0, which includes leveraging tools like Vanta for operational efficiency. The discussion also covers the challenges and considerations for organizations in migrating to v4.0, including the potential complexity of the new customized validation controls and the importance of reevaluating whether handling card data directly is necessary. The episode concludes with advice on engaging with QSAs and considering the strategic outsourcing of card data processing to reduce compliance burdens and associated risks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.