Home | Contact | Advertising
SmartBiz
Members Login:
Sign Up Forgot?
BUSINESS TOOLS
Productivity
Accounting
CRM
Utilities
ONLINE BUSINESS
E-Commerce
Website Creation
Auction Strategies
BITS & BYTES
PCs & Online Equipment
Mobility
Online Software & OS
Telecommunications
SALES & MARKETING
Email Marketing
Advertising
PR
Selling
BUSINESS STRATEGIES
Smart Answers
Management
Finance
Human Resources
Case Studies
FORUMS & RESOURCES
Smart Blog
Tools and Calculators
Smart Voices Forum
Business Partner Forums
Legal & Business Forms
News Feeds


 
Internet Technology Resources For Startup and Small Businesses
Search SmartBiz:
Forms and
Downloads
Free
White Papers
Special
Offers
SmartBiz
Blog
Free Email
Newsletters

SmartBiz IT Research Library



Help | Advanced Search
What's New?
What's Popular?


PCI's False Dilemma: Code Review or Application Firewall?
sponsored by Imperva
Posted:  08 Oct 2008
Published:  08 Oct 2008
Format:  PDF
Length:  4   Page(s)
Type:  White Paper
Language:  English


ABSTRACT:
For organizations attempting to secure their Web applications to meet compliance standards, PCI regulations present a choice of two options: Perform a code review or install a WAF. This, however, is a false choice. The best course of action is to do both. Requirement 6.6 of PCI DSS specifies the means for protecting Web-facing applications, either by "Having all custom application code reviewed for common vulnerabilities by an organization that specializes in application security" or by :installing an application layer firewall in front of Web-facing applications." This short-worded requirement has raised one of the largest PCI debates: Which method should be put in place, a code review or a Web application firewall (WAF)?


Author

Amichai Shulman
CTO ,  Imperva
Amichai Shulman is CTO of application data security vendor Imperva and director of the Imperva Application Defense Center, an application and database security research organization.



BROWSE RELATED RESOURCES
Compliance (Systems Operations) | Compliance Best Practices | Data Security | Databases | Payment Card Industry | Payment Card Industry Data Security Standard Compliance | Security Software

View All Resources sponsored by Imperva

Library Home | Advertise with Us | Product Library
A Service of Bitpipe




Home | Contact | Advertising
© 2006-2008 SmartBiz. All rights reserved. Privacy Statement and Terms of Service
Home | Business Tools | Online Business | Bits & Bytes | Sales & Marketing | Business Strategies | Forums & Resources
Email Driven By: Hosted By:   Design By:
 
XML LogoRSS Logo
Receive our stories via SmartBiz XML/RSS feeds.
Include our stories on your website through SmartBiz javascript content feeds.