---
title: PCI DSS Version 4 – Controversial Topics with The PCI Dream Team
description: The discussion gets heated as we dive deeper into controversial topics surrounding PCI DSS Version 4.
image: https://www.truvantis.com/hubfs/Blogs/PCI%20Dream%20Team%20Pt%203%20(3).png
---

[![truvantis-logo-reverse@2x](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-reverse@2x.png?width=1117&height=250&name=truvantis-logo-reverse@2x.png "truvantis-logo-reverse@2x")](https://www.truvantis.com)

[![truvantis-logo-main@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?width=1117&height=250&name=truvantis-logo-main@2x-1.png "truvantis-logo-main@2x-1")](https://www.truvantis.com/)

**

## Blog

![](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-main@2x-1.png?length=200)

# PCI DSS Version 4 – Controversial Topics with The PCI Dream Team

 August 3, 2023

The Truvantis Risk Radar welcomed the PCI Dream Team to the first stop of their 2023 book tour. Their new book is called, “The Definitive Guide to PCI DSS Version 4 ”.  The authors have more than 50 years of combined PCI experience. When it comes to PCI DSS, they’ve seen it all, been there, and done that and are sharing their combined knowledge with us to make our PCI journeys easier. 

In the final session of our three part interview, the discussion gets heated as we dive deeper into controversial topics surrounding PCI DSS Version 4. 

“11.6.1 is a new requirement to deploy a change-and-tamper detection mechanism to alert for unauthorized modifications to the HTTP headers and contents of payment pages as received by the consumer browser. …this is a really big deal and should be considered in conjunction with PCI DSS 6.3.4 regarding script injection in client-side web browsers.”“Generally speaking, the client-side web browser attack surface has been completely overlooked as a threat landscape except by malware authors, the hacking community, social media, and mass marketers.”  - The Definitive Guide to PCI DSS Version 4 -pg. 171

![](https://www.truvantis.com/hs-fs/hubfs/undefined-Aug-02-2023-11-01-01-5720-PM.png?width=280&height=291&name=undefined-Aug-02-2023-11-01-01-5720-PM.png)

“If you get fifty QSAs (Qualified Security Assessor), you'll have at least, five different opinions, all of them valid.” – Ben Rothke on the Truvantis Risk Radar show. 

“I know in a number of instances, organizations are probably going to need all of that time in order to get them addressed, particularly the service providers, because service providers are the ones that are going to get hurt the most. The merchants of the world, they've reduced their scope down to almost nothing.” – Jeff Hall 

“Our clients tell us stuff that is just insane. And likewise, some of the stuff from the Council is not easily interpreted.”  

“One of the big things with Version 4 is the so-called targeted risk analysis, the old wording would say periodically do this. There's more clarification and now people are going to have to do a targeted risk analysis.” – Art Cooper 

## Listen to the Full Interview  

For the full interview please visit The Truvantis Risk Radar [YouTube](https://www.youtube.com/watch?v=Qk6TIPJyfqQ)  channel or listen to the [podcast](https://www.truvantis.com/podcast#The_PCI_Dream_Team:_Part_3_-_Controversial_Topics_with_The_PCI_Dream_Team). 

## About Truvantis 

Truvantis® is a security, privacy and compliance consulting organization providing best-in-class services to secure your organization's infrastructure, data, operations and products. We specialize in helping our clients improve their cybersecurity posture by implementing testing, auditing and operating information security programs. 

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/da1c8e0b-80c3-43e3-9677-9e07187d90f8.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/da1c8e0b-80c3-43e3-9677-9e07187d90f8)

### References: *‘*

- *The Definitive Guide to PCI DSS Version 4’* by Arthur B. Cooper, Jeff Hall, David Mundhenk, Ben Rothke, [https://link.springer.com/book/10.1007/978-1-4842-9288-4](https://link.springer.com/book/10.1007/978-1-4842-9288-4)
- [The Truvantis Risk Radar show](https://www.youtube.com/@truvantis)

#### Related Articles By Topic

[PCI DSS](https://www.truvantis.com/blog/tag/pci-dss)

### Subscribe Here!

### Recent Posts

### Related Articles By Topic

- [Security Program (76)](https://www.truvantis.com/blog/tag/security-program)
- [vCISO (38)](https://www.truvantis.com/blog/tag/vciso)
- [CISO (35)](https://www.truvantis.com/blog/tag/ciso)
- [PCI DSS (28)](https://www.truvantis.com/blog/tag/pci-dss)
- [SOC2 (28)](https://www.truvantis.com/blog/tag/soc2)
- [Penetration Testing (27)](https://www.truvantis.com/blog/tag/penetration-testing)
- [Privacy (26)](https://www.truvantis.com/blog/tag/privacy)
- [Risk Assessment (19)](https://www.truvantis.com/blog/tag/risk-assessment)
- [CIS Controls (12)](https://www.truvantis.com/blog/tag/cis-controls)
- [Red Teaming (8)](https://www.truvantis.com/blog/tag/red-teaming)
- [HIPAA (7)](https://www.truvantis.com/blog/tag/hipaa)
- [Threat Intelligence (7)](https://www.truvantis.com/blog/tag/threat-intelligence)
- [ISO27001 (6)](https://www.truvantis.com/blog/tag/iso27001)
- [CCPA (5)](https://www.truvantis.com/blog/tag/ccpa)
- [CPRA (2)](https://www.truvantis.com/blog/tag/cpra)
- [GDPR (2)](https://www.truvantis.com/blog/tag/gdpr)
- [Ransomware (2)](https://www.truvantis.com/blog/tag/ransomware)
- [Red Team (2)](https://www.truvantis.com/blog/tag/red-team)
- [HITRUST (1)](https://www.truvantis.com/blog/tag/hitrust)

[See all](https://www.truvantis.com/blog/pci-dss-version-4-controversial-topics-with-the-pci-dream-team#)

Contact Us

Ask us about planning your PCI DSS 4.0 transition

[![Schedule a call](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/125e3f02-ba89-460a-a1fb-d9059cd96dbb.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/125e3f02-ba89-460a-a1fb-d9059cd96dbb)

[![Contact Us](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4366475/ccf084a3-d095-4418-80d6-891f8fdade46.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4366475/ccf084a3-d095-4418-80d6-891f8fdade46)

### Recent Articles

![Truvantis - Cybersecurity Maturity - One Size Does Not Fit All ](https://www.truvantis.com/hubfs/Blogs/Cybersecurity%20Maturity%20-%20One%20Size%20Does%20Not%20Fit%20All.png)

 PCI DSS, CIS Controls, Security Program, Privacy, ISO27001 

[ Cybersecurity Maturity - One Size Does Not Fit All – Rick Folkerts ](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

 It's common knowledge that enterprise organizations need effective security, privacy and compliance programs to survive and grow. There are a handful of generic best practices but beyond that, cybersecurity programs must be tailored to...

[Read more **](https://www.truvantis.com/blog/cybersecurity-maturity-one-size-does-not-fit-all-rick-folkert)

![The Silver Bullet Defense to Ransomware – by Andy Cottrell](https://www.truvantis.com/hubfs/Blogs/The%20Silver%20Bullet%20Defense%20to%20Ransomware%20%E2%80%93%20by%20Andy%20Cottrell.png)

 Ransomware 

[ The Silver Bullet Defense to Ransomware – by Andy Cottrell ](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

 In an era of cost-cutting, downsizing and generally insufficient budgets for everything, we are often asked, what is the one, main thing to do to protect against a ransomware attack? According to Statista, in 2022, there were 493.33 mi...

[Read more **](https://www.truvantis.com/blog/the-silver-bullet-defense-to-ransomware-by-andy-cottrell)

![Cryptographic Agility – by Jeff Hall (the ’PCI Guru’)](https://www.truvantis.com/hubfs/Blogs/Cryptographic%20Agility%20%E2%80%93%20by%20Jeff%20Hall%20(the%20%E2%80%99PCI%20Guru%E2%80%99).png)

 Security Program 

[ Cryptographic Agility – by Jeff Hall (the ’PCI Guru’) ](https://www.truvantis.com/blog/cryptographic-agility)

 With the advent of quantum computing, a new threat has been added to the information security mix. The threat is today’s secure cryptography may not be secure once quantum computers reach their potential. The threat to cryptography has...

[Read more **](https://www.truvantis.com/blog/cryptographic-agility)

[![truvantis-logo-white@2x-1](https://www.truvantis.com/hs-fs/hubfs/Truvantis%20Logo/truvantis-logo-white@2x-1.png?width=1117&height=250&name=truvantis-logo-white@2x-1.png "truvantis-logo-white@2x-1")](https://www.truvantis.com/)

[info@truvantis.com](mailto:info@truvantis.com)

+1 (415) 422-9844

<https://www.facebook.com/truvantis> <https://www.linkedin.com/company/truvantis> <https://twitter.com/truvantis?lang=en>

© 2024 Truvantis, Inc All Rights Reserved.

[Privacy Policy](https://www.truvantis.com/privacy-policy)    [Terms of Service ](https://www.truvantis.com/terms-of-service)

![](https://px.ads.linkedin.com/collect/?pid=2614233&fmt=gif) ![](https://ws.zoominfo.com/pixel/dnjpprEKcMtv41HRInFR)