PCI Compliance Series: 6.6 Roundup
Monday, June 23rd, 2008Security Ninja offers up these four tips:
1. Manual review of application source code
2. Proper use of automated application source code analyzer (scanning) tools
3. Manual web application security vulnerability assessment
4. Proper use of automated web application security vulnerability assessment (scanning) tools
On Tray Ford’s blog, there is mention of a supplement that was released to help clarify 6.6. It is used as a tool to help understand the requirement, although “in no way replaces or supersedes Requirement 6.6 in the Data Security Standard.”
Finally, I took to YouTube to find some helpful information about PCI and I stumbled upon the videos below.
PCI DSS Explained
PCI 6.6 Compliance
Becoming PCI Compliant (and using the right point of sale)
