Ethical Hacker Community Forums

Ethical Hacking Discussions and Related Certifications => Network Pen Testing => Topic started by: BillV on July 02, 2008, 07:45:12 AM



Title: New PCI DSS Requirement
Post by: BillV on July 02, 2008, 07:45:12 AM
More good news for security testers...

Quote
The Payment Card Industry Data Security Standard (PCI DSS), as of Monday, states that web application security testing be upgraded from a best practice to a requirement. (Section 6.6)

Full SC Magazine Article Here (http://www.scmagazineus.com/Deadline-arrives-for-latest-PCI-standard-requirement/article/111977/?DCMP=EMC-SCUS_ITSecurityandFinance)

BillV


Title: Re: New PCI DSS Requirement
Post by: vijay2 on July 02, 2008, 08:42:57 AM
ummm looks like its the right time to get in webapp security. I am sure that there will be alots of business generated from this :)

Time to start a company and use the contacts.


Title: Re: New PCI DSS Requirement
Post by: jason on July 03, 2008, 10:37:38 PM
This is all well and good, as long as the companies are actually complying with it. In the case of the TJX breach, they were in violation of 9 of the 12 security areas that are mandated by PCI.