Secure Coding mailing list archives

darkreading: PCI, web app firewalls, and software security


From: gem at cigital.com (Gary McGraw)
Date: Mon, 10 Dec 2007 15:19:35 -0500

hi sc-l,

My November column (which just went up today?!) is about following the spirit of PCI compliance versus checking the 
box.  I even have something nice-ish to say about web app firewalls.

http://www.darkreading.com/document.asp?doc_id=140979&WT.svl=column1_1

For those of you involved in PCI compliance activities, how many have seen them spearhead real software security?  How 
about box checking?  I would love to see an informal poll.

gem

company www.cigital.com
podcast www.cigital.com/silverbullet
blog www.cigital.com/justiceleague
book www.swsec.com



Current thread: