Monday, October 6, 2008

PCI DSS Version 1.2 is released

Well, the much anticipated DSS standard update to 1.2 was finally released as promised on October 1. Much of the changes is cosmetic and clarifies a lot of wording. Only a couple of changes actually change anything and most of them are related to wireless technologies. One of the ones that comes to mind is the removal of the requirement to not broadcast the wireless SSID. There are so many ways to get that information that it doesn't make a lot of difference either way. Not broadcasting the SSID would only protect you from the simplest of attackers with NO knowledge at all. Hardly the case in today's world.

0 comments:

Post a Comment