|
|
|
|
|
by akshatpradhan
4063 days ago
|
|
>If you have to pick exactly /one/ thing to do in addition to (or instead of) PCI, building thorough automated security testing into your SDLC process is it. I don't understand how SDLC secure testing is an addition to PCI when its really a sub requirement of PCI (Req 6 which addresses SDLC and secure code testing) I'm going to rephrase because I'm still confused: You're saying that in addition to doing PCI, I should do a sub requirement of PCI. Why does that sound like circular logic to me? |
|
Reference: https://www.pcisecuritystandards.org/documents/pci_dss_v2.pd...