The Payment Card Industry Data Security Standard (PCI DSS) is often perceived as a highly rigid and prescriptive standard, leading many organisations to believe there is only one way to achieve compliance. In reality, PCI DSS v4.0 provides several mechanisms that allow organisations to meet security objectives in a way that aligns with their technology, risk profile and operational requirements.
This session challenges the perception that PCI DSS is a one-size-fits-all standard and explores how compliance requirements can be met in a way that works for your business. Join PCI DSS Qualified Security Assessor (QSA) Alastair Stewart as he explains how customised approaches, compensating controls and targeted risk analyses can provide flexibility without compromising security or compliance.
Agenda
- What is PCI DSS v4.0 and Why is it Often Viewed as Prescriptive
- Security Objectives vs Prescribed Controls
- When to Use a Customised Approach
- How Compensating Controls Can Help
- Making Effective Use of Targeted Risk Analyses
- The Role of the Assessor
- Flexibility in Practice
- Common Pitfalls to Avoid
- Q&A
Register for the event
Please note, we can only process business email addresses.
Did you miss the live event? Don't worry. We are recording the webinar, and it will be publicly available one month after the webinar. If you would like to watch the recording shortly after the live session, please contact webinars@urmconsulting.com, and our team will get in touch to provide access to the recording.
Did you miss the live event? Do not worry. We have recorded the webinar for you. Please watch the introduction to the webinar below. For the full recording please register using the form below the video.
Please register using the form below and we will provide you with the link to the recorded webinar.
Register to access full recording
Please note, we can only process business email addresses.

