WebApp Sec mailing list archives

PCI - Visa / MC / Amex merchant security standards


From: "Andrew van der Stock" <vanderaj () greebo net>
Date: Wed, 9 Feb 2005 11:08:30 +1100 (EST)

Ralf Durkee noted in a post to OWASP-Chapters that the payment card
industry (PCI, essentially Visa / MC / Amex and others) have a security
standard out. I saw the draft of this last year when I was discussing my
credit card handling section with Visa.

I didn't realise that it was out in final form. You can get it from here:

http://usa.visa.com/download/business/accepting_visa/ops_risk_management/cisp_PCI_Data_Security_Standard.pdf

The fundamental concepts in this standard are now in the Guide 2.0 as of
last week, but I'll edit my text into line with the final standard.

Also note that they mention OWASP Top 10 explicitly! Yay!

thanks,
Andrew


Current thread: