Expand my Community achievements bar.

Join us on September 25th for a must-attend webinar featuring Adobe Experience Maker winner Anish Raul. Discover how leading enterprises are adopting AI into their workflows securely, responsibly, and at scale.

How are you all preparing for the new PCI requirements which include CSP and SRI?

Avatar

Level 5

Hey all! With the new PCI requirements coming up, I was curious with what everyones plans were with their Data Collection integrations.

Are you switching over to Self Hosting as opposed to Adobe hosting? Separating out your payment screens to avoid the concerns with SPAs?

We're trying to determine which plan forward is the correct one - and I was curious what the Community was doing!


Topics

Topics help categorize Community content and increase your ability to discover relevant content.

2 Replies

Avatar

Level 10

Could you explain what is PCI? It affects US market only? 

 

Avatar

Level 5

It is the Payment Card Industry which is global.

 

The new enforcements as a part of PCI DSS 4.0 require integration of CSP (content security policy) which is supported cleanly by launch and also SRI (Subresource Integrity) which requires JS scripts that run to have an integrity attributed applied that matches back against a pregenerated hash. 

 

This presents some significant challenges with a DTM like Data Collection (Launch) due to the nature of ad hoc scripts that run when users take specific actions. If you're using Adobe hosted launch, as of right now there is not a viable solution I'm aware of to be able to meet SRI Compliance - hence my reaching out to the community.