« Are We Making A Dent Yet? | Main | Brighter days ahead »

Keep My Credit Card Safe

The PCI Security Standards Council, which maintains a set of security requirements for nearly every type of organization involved in credit card transactions, recently updated their Data Protection Standards to include a mandate that all regulated applications either have software security experts perform a code review for security vulnerabilities or use an application firewall to protect web-facing applications. This guideline is only a best practice for now, but on June 30th, 2008 it will become a mandatory requirement.

It's fantastic that a standard as impactful as PCI, which already included language that addressed software security concerns, is progressing to include accountability in the form of code review. However, it's concerning that the standard calls for an either/or choice between an activity and a technology that are not at all parallel. Application firewalls are effective at preventing certain kinds of attacks, but they are not an adequate substitute for building secure software. Code review is an essential part of secure development and should be mandatory for sensitive applications, like the ones governed by the PCI standards.

TrackBack

Listed below are links to weblogs that reference Keep My Credit Card Safe:

» http://1raindrop.typepad.com/1_raindrop/2006/10/i_am_no_complia.html from 1 Raindrop
I am no compliance guru, but I have been involved in several efforts that were associated with compliance. So far of the ones I have seen I happen to think that the market-driven PCI DSS is the most effective. Perfect? Not even close, but at least it i... [Read More]

Presented By

About

This page contains a single entry from the blog posted on September 28, 2006 6:54 PM.

The previous post in this blog was Are We Making A Dent Yet?.

The next post in this blog is Brighter days ahead.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.34