PCI’s False Dilemma: Code Review or Application Firewall?
Web application vulnerabilities put critical business applications and back-end databases at risk from attack, theft and fraud. The Payment Card Industry Data Security Standard, which recognizes the threat Web application vulnerabilities pose to credit card data, allows organizations to choose between two mitigation techniques. Requirement 6.6 of PCI DSS specifies the means for protecting Web-facing applications, either by code review or by installing an application layer firewall.
No Responses to “PCI’s False Dilemma: Code Review or Application Firewall?”
Responses are currently closed, but you can trackback from your own site.

