From: The Register
Third parties must comply to new standard
Third-party providers will face more stringent regulations as part of a revamp in payment card industry regulations due to go into full effect in the new year.
The new Payment Card Industry Data Security Standard 3.0 (PCI 3.0) will be mandatory for all businesses that store, process or transmit payment card information beginning 1 January 2015. The revamped standard includes requirements aimed at third party providers.
The changes follow a string of high profile breaches, several of which including the most serious Target and Home Depot breaches were subsequently traced back to lax security controls at third party providers. In the case of Target, its heating and air conditioning subcontractor was implicated in the subsequent hack and the retail chain.
Leave a Reply