Payment Card Industry Mandate Stresses Importance of Web Application Security: Recommended Becomes Required
by Danny Allan - IBM Rational's Director of Security Research - Tuesday, 10 June 2008.
Bookmark and Share
As PCI recommends, the use of automated scanning tools makes it possible to test for security from the very beginning and continually throughout the software development lifecycle, preventing vulnerabilities from turning into threats. Dealing with the root of the problem by embedding security analysis into the lifecycle of an application will not only guarantee improved security but it will save your organization time and money.

Smart companies will use the latest PCI upgrade as the motivation for putting their entire security and privacy compliance programs in order, building in security assessment from the ground up. Complying once and then forgetting about it until the next audit is bad practice. To successfully drive more business through the online channel, organizations cannot ignore Web privacy and application security. Only through a combination of dedication, education, business process improvement and risk management technology will firms be able to properly protect and control the online channel.


Meeting the PCI requirements for Web application security by employing code review and a Web application firewall is a great starting point, but to fully protect consumer data and implement a comprehensive online risk management strategy, organizations must also enforce policies that include ongoing compliance monitoring procedures.

Spotlight

Review: Logging and Log Management

Posted on 22 May 2013.  |  Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Thu, May 23rd
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //