Security experts say they’re pleased with many of the changes and additions in this year’s update to Payment Card Industry’s Data Security Standard and Application Data Security Standards. But they also note some glaring omissions and express concern that neither standard has much enforcement action behind it. The new version of the two standards were issued Nov. 7, but they don’t take effect until January and they won’t be enforced until 2015. The primary problem with PCI’s approach to security is that it is not risk-based, an expert says.”]
Source: https://www.govinfosecurity.com/critiquing-new-version-pci-dss-a-6208

