The PCI Security Standards Council (SSC) has always sought industry feedback to help shape its Data Security Standard (DSS). That’s why the latest iteration offers more flexibility for complying organizations. However, greater flexibility doesn’t necessarily mean an easier pathway to compliance. As a new guidance document from the PCI SSC attests, the resources, documentation, and testing required to stray from the defined approach can be onerous.
Organizations should bear this in mind when weighing their options, and consider how a best practice tokenization-first approach supported by comforte TAMUNIO could simplify compliance.
The new guidance focuses on compensating controls and the customized approach. They do not mean the same thing, although both point in the same direction for PCI DSS—more flexibility and more choice for complying organizations.
The customized approach is new with PCI DSS 4.0. Whereas the traditional defined approach requires organizations to follow the standard prescriptive requirements and testing procedures, the customized approach is different. It allows complying organizations to meet the security objectives of PCI DSS requirements in alternative ways, using new technologies, approaches and architectures where they see an advantage in doing so.
Let’s be clear though, these new customized controls must still be understandable, testable, repeatable, and evidence backed. The approach is therefore applicable mainly to mature organizations. As PCI SSC states: “The customized approach is most successful when the entity has robust security processes and strong risk management practices and is able to effectively design, document, test, and maintain security controls to meet that objective.”
Compensating controls precede PCI DSS 4.0. They allow organizations working within the defined approach a way to use alternative controls when they have a “legitimate and documented technical or business constraint” which prevents them from meeting defined requirements. This often happens when legacy technology or processes won’t allow for required updates.
However, it’s important to remember that, here too, there are caveats. Every compensating control must be designed and evidenced, and it must be annually reviewed and validated by an independent assessor. In environments with legacy kit, this can add cost, complexity and uncertainty to the compliance process. Every year, the organization must prove that its compensating controls are still able to fulfil the relevant PCI DSS security objectives that couldn’t otherwise be met.
In summary:
When it comes to cardholder data, tokenization is a PCI DSS-recognized mechanism for protecting data that could help to reduce the scope, complexity, and cost associated with the compliance process. It works by replacing the primary account number (PAN) with a random string of characters which, if intercepted or otherwise obtained by threat actors, would be worthless. That means these tokens are considered outside the scope of PCI DSS.
Tokenization could in theory be used as a compensating control, if another control written in the PCI DSS 4.0 defined approach could not be deployed. In reality though, it should be viewed less as a temporary workaround and more as a deliberate architectural choice for driving long-term security, compliance, and business benefits. Tokenization not only protects the data but does so in a way that it can still be used for AI and analytics, preserving utility for business users.
The comforte TAMUNIO platform uses AI to continuously discovery and classify data wherever it lives in the enterprise. It offers vaultless tokenization and format-preserving encryption as options to protect that data in line with policy and compliance requirements. This enables organizations to reduce the potential burden associated with compensating controls and customized approaches and instead focus on reducing risk directly by protecting their PANs and reducing exposure.
TAMUNIO offers other ways to meet the requirements of a defined approach, such as via centralized key management, and Zero Trust support. It’s also focused on the future, with support for post-quantum encryption. This means that, as PCI DSS requirements change, customers can stay one step ahead with future-proof data protection.
More fundamentally though, TAMUNIO offers an opportunity not just to comply with the letter of the law. It’s about providing a platform for business growth built on secure and solid foundations.