Find White Papers
Home
About Us
List Your Papers
    
> HP - Enterprise Security > Passing PCI Compliance Section 6.6: Code Reviews and Application Firewalls

Passing PCI Compliance Section 6.6: Code Reviews and Application Firewalls

White Paper Published By: HP - Enterprise Security

If your company stores or processes credit card information, you must be able to demonstrate compliance with the Payment Card Industry (PCI) Data Security Standards (DSS). These standards include requirements for security management, policies, procedures, network architecture, design, and other critical protective measures. They also include one very prescriptive requirement:  Section 6.6 mandates that organizations secure all Web applications by conducting a code review or installing an application layer firewall. Companies have had a very difficult time passing the other parts of Section 6 and they have experienced a rising number of data breaches. Unless companies take 6.6 seriously, PCI compliance failure rates, and data breaches, will continue to grow.  Read this whitepaper to gain an overview of best practices to pass Section 6.6 and an understanding of the technology available to you.



Tags : 
business risk, , security, application security, audit, risk, vulnerabilities, fortify

HP - Enterprise Security
Published:  Oct 16, 2008
Type:  White Paper
Length:  14 pages

WWHHIITTEE PPAAPPEERR
Passing PCI Compliance
Section 6.6Code Reviews and Application Firewalls
Taylor McKinleyProduct Marketing ManagerFortify
Passing PCI Compliance Section 6.6 WWW.FORTIFY.COM 1WHITE PAPER
Passing PCI Compliance Section 6.6Code Reviews and Application Firewalls
Table of Contents
3 Current Overview of PCI and Section 6.64 Learning from 2006/2007 Failures5 Use of Multiple Techniques Is the Best Approach6 If You Can Choose Only a Single Approach®9 Overview of Fortify 36010 How Fortify 360 Can Help Pass Section 6.6 and Other Sections14 Conclusion14 References
Executive Summary
If your company stores or processes credit card information, you must be able to demonstrate compliance with the Payment Card Industry (PCI) Data Security Standards (DSS). These standards, created by representatives of the credit card companies, include requirements for security management, policies, procedures, network architecture, design, and other critical protective measures. They also include one very prescriptive requirement that goes into effect on June 30, 2008. Section 6.6 mandates that organizations secure all Web applications by conducting a code review or installing an application layer firewall. To date, companies have had a very difficult time passing the other parts of Section 6. They've also experienced a rising number of data breaches. Unless companies take 6.6 seriously, PCI compliance failure rates, and data breaches, will continue to grow. This white paper provides an overview of how best to pass Section 6.6, shares feedback from failed audits in 2006 and 2007, outlines the pros and cons of fixing the code versus installing an application firewall, and introduces Fortify's Business Software Assurance ®solution, Fortify 360, which delivers source code analysis, Web application testing, and application firewall technology.
Passing PCI Compliance Section 6.6 WWW.FORTIFY.COM 2WHITE PAPER
With the June Current Overview of PCI and Section 6.630, 2008, deadline In 2004, the major credit card companies developed the first integrated set of IT security passed, companies standards for all online merchants. These standards were revised in 2006, and the PCI Council, are quickly trying to an independent entity, was formed to manage and enforce these standards. The complete address Section 6.6. standards can be read at: https://www.pcisecuritystandards.org/tech/index.htmIn the newest revision (version 1.1), the PCI Council made several minor edits and added a new initiative. This new initiative - Section 6.6 - started as a best practice and became mandatory on June 30, 2008. This section reads:"Ensure that all web-facing applications are protected against known attacks by applying either of the following methods:. Having all custom application code reviewed for common vulnerabilities by an organization that specializes in application security 1. Installing an application layer firewall in front of web-facing applications" On April 22, 2008, the PCI Council released a supplement document to clarify this section. The key points were:. Automated source code analysis tools can be used to meet this requirement. Automated Web application scanning tools can be used to meet this requirement. If either of these tools are used, or an application firewall is deployed, they must be configured, set up, and managed appropriatelyWith the June 30, 2008, deadline passed, companies are quickly trying to address Section 6.6.
Passing PCI Compliance Section 6.6 WWW.FORTIFY.COM 3WHITE PAPER
Learning from 2006/2007 Failures
Over the last two years, many companies have failed their PCI audits. A careful look back will Many companies are reveal that Section 6?-?even without 6.6 being mandatory?-?proved to be one of the most failing their audits challenging requirements. This includes mandates such as "developing all Web applications and are getting based on secure coding guidelines." The following statistics demonstrate how difficult this hacked because they section has become.over rely on one . 56% percent of organizations fail Section 6: Develop and maintain secure systems and approach, namely applications. Web application -?VeriSign
scanning. This is one . Poorly coded Web applications leading to SQL injection vulnerabilities is one of the top five of the key reas... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search