<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI Extends Its Reach to Application Security</title>
	<atom:link href="http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: coder</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-2288</link>
		<dc:creator>coder</dc:creator>
		<pubDate>Tue, 21 Oct 2008 04:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-2288</guid>
		<description>Item 6.6 may be mandatory, but you don&#039;t have to do it....
https://www.pcisecuritystandards.org/pdfs/infosupp_6_6_applicationfirewalls_codereviews.pdf</description>
		<content:encoded><![CDATA[<p>Item 6.6 may be mandatory, but you don&#8217;t have to do it&#8230;.<br />
<a href="https://www.pcisecuritystandards.org/pdfs/infosupp_6_6_applicationfirewalls_codereviews.pdf" rel="nofollow">https://www.pcisecuritystandards.org/pdfs/infosupp_6_6_applicationfirewalls_codereviews.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero in a bit &#187; WAF Better Than Code Review? Think Again.</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-947</link>
		<dc:creator>Zero in a bit &#187; WAF Better Than Code Review? Think Again.</dc:creator>
		<pubDate>Wed, 16 Apr 2008 02:00:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-947</guid>
		<description>[...] is why I argued, a while back, that a WAF really should be considered a compensating control since it is more of a [...]</description>
		<content:encoded><![CDATA[<p>[...] is why I argued, a while back, that a WAF really should be considered a compensating control since it is more of a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Blog &#187; Network Security Podcast, Episode 78</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-697</link>
		<dc:creator>Network Security Blog &#187; Network Security Podcast, Episode 78</dc:creator>
		<pubDate>Sat, 05 Jan 2008 21:39:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-697</guid>
		<description>[...] PCI Extends its reach to application security [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI Extends its reach to application security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Infosec Pals</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-581</link>
		<dc:creator>Infosec Pals</dc:creator>
		<pubDate>Thu, 11 Oct 2007 04:14:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-581</guid>
		<description>&lt;strong&gt;PCI Compliance to mandate Application Security Testing...&lt;/strong&gt;

Chris Eng has an excellent post on his observations from the PCI community meeting in Toronto. To quote from his blog entry at: http://www.veracode.com/blog/?p=63
Requirement 6.6 of the PCI-DSS becomes mandatory in June 2008 and requires all web-facing...</description>
		<content:encoded><![CDATA[<p><strong>PCI Compliance to mandate Application Security Testing&#8230;</strong></p>
<p>Chris Eng has an excellent post on his observations from the PCI community meeting in Toronto. To quote from his blog entry at: <a href="http://www.veracode.com/blog/?p=63" rel="nofollow">http://www.veracode.com/blog/?p=63</a><br />
Requirement 6.6 of the PCI-DSS becomes mandatory in June 2008 and requires all web-facing&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Podcast, Episode 78 &#124; securosis.com</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-572</link>
		<dc:creator>Network Security Podcast, Episode 78 &#124; securosis.com</dc:creator>
		<pubDate>Tue, 25 Sep 2007 23:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-572</guid>
		<description>[...] PCI Extends its reach to application security [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI Extends its reach to application security [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI DSS Compliance Demystified &#187; Blog Archive &#187; Community Meeting in Toronto</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-570</link>
		<dc:creator>PCI DSS Compliance Demystified &#187; Blog Archive &#187; Community Meeting in Toronto</dc:creator>
		<pubDate>Tue, 25 Sep 2007 18:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-570</guid>
		<description>[...] the PCI SSC Community Meeting in Toronto went very well.  Some people blogged about it. There is a great post about the future inclusion of PA-DSS into the PCI standard.  This is a long planned event that will take time to test and [...]</description>
		<content:encoded><![CDATA[<p>[...] the PCI SSC Community Meeting in Toronto went very well.  Some people blogged about it. There is a great post about the future inclusion of PA-DSS into the PCI standard.  This is a long planned event that will take time to test and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Ticking Time Bomb - PCI Application Security &#171; Mark Curphey - SecurityBuddha.com</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-569</link>
		<dc:creator>The Ticking Time Bomb - PCI Application Security &#171; Mark Curphey - SecurityBuddha.com</dc:creator>
		<pubDate>Tue, 25 Sep 2007 08:35:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-569</guid>
		<description>[...] morning I was reading an excellent post by Chris Eng about a recent PCI Council meeting he attended. Its&#8217;s surely hard for anyone to criticize the [...]</description>
		<content:encoded><![CDATA[<p>[...] morning I was reading an excellent post by Chris Eng about a recent PCI Council meeting he attended. Its&#8217;s surely hard for anyone to criticize the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: September 21st</title>
		<link>http://www.veracode.com/blog/2007/09/pci-extends-its-reach-to-application-security/comment-page-1/#comment-567</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: September 21st</dc:creator>
		<pubDate>Fri, 21 Sep 2007 13:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=63#comment-567</guid>
		<description>[...] PCI Extends Its Reach to Application Security [...]</description>
		<content:encoded><![CDATA[<p>[...] PCI Extends Its Reach to Application Security [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

