PCI compliance help via Fortify software

Article

PCI compliance help via Fortify software

SearchSoftwareQuality.com Staff

Fortify Software Inc. is making Payment Card Industry Data Security Standard (PCI DSS) 6.6 compliance easier for its customers with the addition of a project template that gives developers, auditors, and managers a PCI-centric view into the security of their software systems.

    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

More information on
PCI DSS compliance
The realities of PCI DSS 6.6 application code reviews

The realities of using WAFs for PCI DSS 6.6 compliance

Beginning June 30, customers using Fortify's cornerstone software security solution, Fortify 360, are able to immediately identify and remediate code level vulnerabilities that violate PCI DSS standards.

Currently, Fortify 360 integrates the results from three analyzers into a central repository where they are separated into folders that correspond to their priority. Fortify 360 offers users the ability to test applications using both static and dynamic analysis capabilities, as well as deploy real-time protection in the form of a software-based application firewall. Fortify representatives say the company is the only one to offer all three solutions.

As of June 30, when section 6.6 of the PCI DSS became mandatory, all merchants are required to implement source code analysis solutions or install a Web application firewall. This is in response to the increase in attacks directed against applications.

In response to the major milestone of section 6.6, Fortify's Security Research Group, working closely with Fortify customers, created an environment for Fortify 360 that both draws attention to critical security flaws and specifically highlights issues that violate the PCI DSS. This new capability for Fortify products is available to customers via download from the Fortify Customer Portal.