PCI DSS version 3.0 and business-as-usual activities, password management, vulnerability assessments and provider compliance etc How are organizations responding to these changes in the compliance standards? Based on global assessments over a 5 year period, how are changes from version 1.2 to 3.0 impacting organisations?