PCI Compliance Series: 6.6 Roundup
Posted Monday, June 23rd, 2008
Categories: PCI.
Security Ninja offers up these four tips:
1. Manual review of application source code
2. Proper use of automated application source code analyzer (scanning) tools
3. Manual web application security vulnerability assessment
4. Proper use of automated web application security vulnerability assessment (scanning) tools
On Tray Ford’s blog, there is mention of a supplement that was released to help clarify 6.6. It is used as a tool to help understand the requirement, although “in no way replaces or supersedes Requirement 6.6 in the Data Security Standard.”
Finally, I took to YouTube to find some helpful information about PCI and I stumbled upon the videos below.
PCI DSS Explained
PCI 6.6 Compliance
Becoming PCI Compliant (and using the right point of sale)
- PCI Compliance Series Part Twelve: Using WSP to help with 6.6 Compliance - June 19th, 2008
- PCI Compliance Series Part Eleven: Link Roundup Examining 6.6 - June 18th, 2008
- PCI Compliance Series: Part Ten - PCI DSS 6.6 Deadline This Summer - June 17th, 2008
- News Release: E-xact Achieves PCI Compliance Again in 2008 - April 14th, 2008
