PCI DSS Applicability

PCI DSS ◽  
2020 ◽  
pp. 195-211
Author(s):  
Jim Seaman
Keyword(s):  
EDPACS ◽  
2009 ◽  
Vol 39 (1) ◽  
pp. 1-9
Author(s):  
The Institute of Internal Auditors
Keyword(s):  

Author(s):  
Shakeel Ali

A rapidly changing face of internet threat landscape has posed remarkable challenges for security professionals to thwart their IT infrastructure by applying advanced defensive techniques, policies, and procedures. Today, nearly 80% of total applications are web-based and externally accessible depending on the organization policies. In many cases, number of security issues discovered not only depends on the system configuration but also the application space. Rationalizing security functions into the application is a common practice but assessing their level of resiliency requires structured and systematic approach to test the application against all possible threats before and after deployment. The application security assessment process and tools presented here are mainly focused and mapped with industry standards and compliance including PCI-DSS, ISO27001, GLBA, FISMA, SOX, and HIPAA, in order to assist the regulatory requirements. Additionally, to retain a defensive architecture, web application firewalls have been discussed and a map between well-established application security standards (WASC, SANS, OWASP) is prepared to represent a broad view of threat classification.


Sign in / Sign up

Export Citation Format

Share Document