In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, examine one of the most frequently misunderstood areas of PCI DSS: the difference between compensating controls and the customised approach. Drawing on their extensive PCI DSS assessment experience, they discuss:
The key differences between compensating controls and customised approaches, and the specific scenarios where each can be usedWhy compensating controls are not a “get out of jail free” card for non-compliance and the strict conditions that must be met before they can be appliedThe legal, regulatory, technical, and financial constraints that may justify the use of compensating controlsHow customised approaches were introduced in PCI DSS v4.0 to support innovative and non-traditional methods of meeting security objectivesWhy customised validations require significant planning, documentation, evidence collection, and assessor involvement before they can be approvedAnd more.If there's a PCI DSS related issue you'd like us to explore, share it with us here here: https://urmconsulting.com/podcasts/pci-dss-compensating-controls-vs-customized-approach
We use listener questions to guide future discussions and ensure our episodes tackle the challenges that matter most to organisations like yours.
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.