Secure Coding mailing list archives

InternetNews Realtime IT News - Merchants Cope With PCI Compliance


From: ljknews at mac.com (ljknews)
Date: Mon, 30 Jun 2008 10:45:56 -0400

At 9:44 AM -0400 6/30/08, Kenneth Van Wyk wrote:

Happy PCI-DSS 6.6 day, everyone.  (Wow, that's a sentence you don't  
hear often.)

http://www.internetnews.com/ec-news/article.php/3755916

In talking with my customers over the past several months, I always  
find it interesting that the vast majority would sooner have root  
canal than submit their source code to anyone for external review.   
I'm betting PCI 6.6 has been a boon for the web application firewall  
(WAF) world.

The "Note:" at the end of PCI DSS (v1.1) 6.6 talks about
"this method" but typographically seems to apply to both
bullets.  Does anyone know what the authors had in mind ?
-- 
Larry Kilgallen


Current thread: