HomeSecurityPCI DSS 3.1 sets deadline for SSL Migration

PCI DSS 3.1 sets deadline for SSL Migration

SSL

SSL: The PCI Security Standards Council (PCI SSC) has released the latest version of the PCI Data Security Standard (PCI DSS) to address security issues related to the Secure Sockets Layer (SSL) protocol.

PCI DSS version 3.1 is available here. The updated version marks the latest security review of SSL, which has been hit by a number of security vulnerabilities such as FREAK and POODLE. Under the revised rules, Secure Sockets Layer and early versions of the Transport Layer Security (TLS)are no longer considered examples of “strong encryption.” Early TLS is defined as TLS v.1.0, as well as version 1.1 in some cases.

The council's move follows the National Institute of Standards and Technology (NIST), which has declared SSL v3.0 unacceptable for data protection due to its "inherent weaknesses." The council has therefore decided to update the protocol.

Under the new rules, companies must update to a more recent version of TLS by June 30, 2016. Before that date, existing applications that use TLS or SSL must formally mitigate the risk with a migration plan. Effective immediately, all new applications must not use TLS or Secure Sockets Layer.

POS and POI terminals such as magnetic card readers or chip card readers, which allow the consumer to make a purchase that can then be verified as not being vulnerable to all known exploits for Secure Socket Layer and Transport Layer Security, can continue to be used as a security check after the appropriate date.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS