White Papers

Information Supplement: Application Reviews and Web Application Firewalls Clarified

Overview Payment Card Industry Data Security Standard (PCI DSS)Requirement 6.6 provides two options that are intended to address common threats to cardholder data and ensure that input to running web applications from untrusted environments is inspected "Top to Bottom." The intent of Requirement 6.6 is to ensure web applications exposed to the public Internet are continually protected against the most common types of threats while running and accepting input. There is a great deal of public information available regarding web application vulnerabilities. This paper provides guidance to assist in determining the best option, which can vary depending on products in use, how an organization procures or develops its web applications, and other factors within the environment.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
PCI Security Standards Council
File Format
PDF
Date Published
Jul 13, 2009
Format
White Papers
Topics
Data Recovery - Security, Firewalls, Security Standards

Similiar White Papers

Demystifying the PCI Data Security Standard for Merchants

Demystifying the PCI Data Security Standard for Merchants

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security practices set forth by American Express,

Publisher: ComplyGuard Networks  |  Tags: data, data security, pci, pci dss

ESG Report: Symantec Sets a Course for Security Leadership with Security 2.0

ESG Report: Symantec Sets a Course for Security Leadership with Security 2.0

Download this Enterprise Strategy Group (ESG) Security Brief to read about Symantec's recent rollout of its newest enter

Publisher: Symantec

Demystifying the PCI Data Security Standard for Service Providers

Demystifying the PCI Data Security Standard for Service Providers

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security practices set forth by American Express,

Publisher: ComplyGuard Networks  |  Tags: data, data security, pci, pci dss

Streamline to Success: The Real Mid-Market Experience: Banking

Streamline to Success: The Real Mid-Market Experience: Banking

Community financial institutions, including retail and commercial banks, savings & loans, and credit unions, along with

Publisher: IBM  |  Tags: information security, pci, sarbanes-oxley

PCI DSS Compliance in the UNIX/Linux Datacenter Environment

PCI DSS Compliance in the UNIX/Linux Datacenter Environment

This document explains how BeyondTrust PowerBroker supports the Payment Card Industry Data Security Standard (PCI DSS) b

Publisher: BeyondTrust  |  Tags: applications, linux, pci, pci dss

PCI Security Standards Council White Papers

Payment Card Industry (PCI) Data Security Standard: Security Assessment Procedures

Payment Card Industry (PCI) Data Security Standard: Security Assessment Procedures

The payment card industry (PCI) denotes the debit, credit, pre-paid, e-purse, ATM, and POS cards and associated business

Publisher: PCI Security Standards Council  |  Tags: atm, pci, pci dss, pos

Ten Common Myths of PCI DSS

Ten Common Myths of PCI DSS

The Payment Card Industry Data Security Standard (PCI DSS) secures cardholder data that is stored, processed or transmit

Publisher: PCI Security Standards Council  |  Tags: data, pci, pci dss

The Prioritized Approach to Pursue PCI DSS Compliance

The Prioritized Approach to Pursue PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) provides a detailed, 12 requirements structure for securing c

Publisher: PCI Security Standards Council  |  Tags: data, data security, pci, pci dss

Information Supplement: Requirement 6.6 Code Reviews and Application Firewalls Clarified

Information Supplement: Requirement 6.6 Code Reviews and Application Firewalls Clarified

The intent of Requirement 6.6 is to ensure web applications exposed to the public Internet are protected against the mos

Publisher: PCI Security Standards Council  |  Tags: applications, pci, source code

Payment Card Industry (PCI) Data Security Standard: Navigating PCI DSS

Payment Card Industry (PCI) Data Security Standard: Navigating PCI DSS

This paper describes the 12 Payment Card Industry Data Security Standard (PCI DSS) requirements, along with guidance to

Publisher: PCI Security Standards Council  |  Tags: applications, authentication, data, network, pci, pci dss