PCI DSS

PCI requires secure applications

The Payment Card Industry Data Security Standard (PCI DSS) has established security requirements for merchants and service providers who do business with the major credit card firms. Since the vast majority of malicious attacks today are directed at applications, PCI DSS requires companies to meet application development security standards to protect customer credit card data and account information from hackers or malicious system intrusion. To achieve PCI DSS compliance, businesses must certify that they can develop and deploy secure applications by ensuring Web applications are not susceptible to common vulnerabilities and that custom application code has been reviewed by independent application security audit experts. For many businesses and merchants around the world, PCI DSS is most effectively and cost-efficiently achieved with Veracode.

Veracode: Application security testing to achieve compliance with PCI DSS

Veracode SecurityReview® for PCI DSS helps companies achieve compliance with the Data Security Standard in a simple and cost-effective process. SecurityReview is an automated, on-demand, application security testing solution that provides code review on an as-needed basis and without the need for costly application security software or time-consuming manual line-by-line analysis. Companies need only submit code through a secure online portal, getting results back within 24 to 72 hours. Veracode's flexibility and ease-of-use enables companies to use SecurityReview at multiple points in the software development process. Veracode's Ratings System offers independent verification of software security based on respected industry standards. There simply is no easier way to achieve PCI DSS compliance than with code security analysis from Veracode.

PCI DSS, application security, and more

In addition to helping to secure PCI DSS compliance, Vercode provides significant benefits in application security:

  • Greater code coverage—While most vulnerability assessment software scans only application source code, Veracode scans code at the binary level. Applications have grown considerably in complexity and frequently comprise code from multiple sources—third-party libraries, open source software, commercial off-the-shelf (COTS) software, and more. Source code for these applications is often unavailable for proprietary reasons. Because Veracode scans binary code—compiled or "byte" code—lack of source code is not an obstacle to reviewing an application. Consequently, Veracode's solution provides 100 percent code coverage, while competing products offer only partial coverage.
  • On-demand analysis—Because Veracode is available as software-as-a-service (SaaS), organizations can use SecurityReview to quickly scale security testing as needed and to rollout global best-practices for application security and IT risk management.

Learn more about PCI DSS solutions with Veracode now

 

Security