Aug 6, 2026 · 37 min · 12 segments
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, share their insights on complying with periodic…
Alistair StewartGuest
Tibor LaczkoGuestAnnieHost
Flexibility was their keyword for version four, I think, wasn't it, Tibor? It was flexibility, isn't it?

I think PCI is, is known to be a very black-and-white standard, so whatever the standard says, you need to do it.

I think the council wanted to show, as you said, a little flexibility to, like, okay, so there are certain things that, you know, you know your organization best, you should be able to decide.

But they still put it in a very controlled manner, right? So you still need to do a targeted risk analysis and so on.

But it ultimately, yeah, because y- you find that they don't update the standard that often.

It's quite a long update cycle, and so it needed more flexibility to be able to cope with changes and new technologies and new systems.

But again, I think the, the important bit is, you know, PCI didn't abandon the set frequencies.

It's just for certain stuff, they allow some flexibility for, for customers or clients.
And are organizations embracing this flexibility, or are most still dev- defaulting to sort of more traditional frequencies, such as quarterly, six-monthly, or annually?

Some of my clients are, you know, when they get the opportunity to, to go, "Well, actually, we wanna do this at a different frequency for this, this, and this reason," they're going with it.

Although, m- I think most of them are still going, "Well, industry standard was six-monthly before this, so we'll keep doing it that way."

Flexibility was their keyword for version four, I think, wasn't it, Tibor? It was flexibility, isn't it?

I think PCI is, is known to be a very black-and-white standard, so whatever the standard says, you need to do it.

I think the council wanted to show, as you said, a little flexibility to, like, okay, so there are certain things that, you know, you know your organization best, you should be able to decide.

But they still put it in a very controlled manner, right? So you still need to do a targeted risk analysis and so on.

But it ultimately, yeah, because y- you find that they don't update the standard that often.

It's quite a long update cycle, and so it needed more flexibility to be able to cope with changes and new technologies and new systems.

But again, I think the, the important bit is, you know, PCI didn't abandon the set frequencies.

It's just for certain stuff, they allow some flexibility for, for customers or clients.
And are organizations embracing this flexibility, or are most still dev- defaulting to sort of more traditional frequencies, such as quarterly, six-monthly, or annually?

Some of my clients are, you know, when they get the opportunity to, to go, "Well, actually, we wanna do this at a different frequency for this, this, and this reason," they're going with it.

Although, m- I think most of them are still going, "Well, industry standard was six-monthly before this, so we'll keep doing it that way."
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.