PCI v2.0 : PCI Security Standards Council Releases PCI DSS 2.0 and PA-DSS 2.0

On 28 october 2010 PCI Security Standards Council, has released version 2.0 of the PCI DSS and PA-DSS standard.

Version 2.0 becomes effective on January 1, 2011, but validation against the previous version of the standard (1.2.1) will be allowed until December 31, 2011.

Version 2.0 does not introduce any new major requirements. The majority of changes are modifications to the language, which clarify the meaning of the requirements and make understanding and adoption easier for merchants. Key revisions serve to reinforce the need for a thorough scoping exercise prior to assessment in order to understand where cardholder data resides; promote more effective log management in securing cardholder data; allow organizations to adopt a risk-based approach when assessing and prioritizing vulnerabilities that is based on their specific business circumstances; and accommodate the unique environments of small merchants to simplify their compliance efforts.

The standards, detailed summary of changes and supporting documentation can be found at https://www.pcisecuritystandards.org/security_standards/documents.php .

(Official Press Release - PDF)

More info:
PCI DSS 2.0 and PA-DSS 2.0 SUMMARY OF CHANGES - HIGHLIGHTS (PDF)
PCI council launches microsite to help small merchants understand updated standards
Things To Look Out For In New PCI Version 2.0
New PCI Standards Finalized
PCI DSS 2.0: PCI assessment changes explained