AUTO-UPDATED

The Scripts on Your Checkout Page Are Now a PCI DSS Problem

Reflectiz has received validation from PCI Qualified Security Assessor Integrity360 Europe for its ability to help merchants meet new PCI DSS v4.0.1 requirements regarding third-party script security.

Key Points

  • PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 mandate that merchants inventory, authorize, and monitor the integrity of all payment-page scripts.
  • Integrity360 Europe confirmed that the Reflectiz platform effectively detects unauthorized script behavior and provides audit-ready evidence for compliance assessments.
  • The platform utilizes agentless monitoring to track script behavior in real-time, addressing the risk of supply-chain attacks where malicious code is injected via trusted vendors.
  • Reflectiz data indicates that approximately 30% of payment-page scripts undergo changes within any two-week period, making manual compliance tracking unsustainable.
  • Merchants using payment iframes must now prove their checkout pages are not susceptible to script hijacking to satisfy updated PCI SSC guidelines.

Why it Matters

These updated PCI standards address the growing threat of web skimming, which has compromised over 100,000 websites and led to massive regulatory fines. By automating script monitoring, businesses can secure their checkout processes against supply-chain vulnerabilities without requiring complex code changes or manual oversight.
Internet Published by info@thehackernews.com (The Hacker News)
Read original