Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

When a PCI QSA and application security collide

by The Gurus
June 26, 2014
in Opinions & Analysis
Share on FacebookShare on Twitter

While application security and payment data compliance are not commonly associated, there are more links than you would expect.
Speaking at the OWASP AppSec conference in Cambridge, Geraint Williams, consultant and QSA said that when assessing PCI certification, he will be looking at the protection of cardholder data within web applications, but there are a series of common problems that he comes across and that can be removed.
He said: “What I am looking for in an audit is do they have policies and procedures in place, and are the people trained? PCI DSS not the best standard for web application security, but it is a minimum standard and I hope processors are securing to minimum standard.”
Highlighting some common failures, Williams pointed at the use of a third party processor or data handler whose “security is usually totally useless” and whose website can be easily redirected to a website controlled by the attacker. “It is about writing applications that make sure any handover is done properly, it falls within the scope of PCI DSS,” he said.
He also pointed at the use of third party adverts which can be infected, and served on e-commerce website, possibly to capture cardholder data. “We want to see everything has been considered within an application and with e-commerce and normal merchants also.”
The biggest concern though is, if you operate a website and you developed the code, can you show you have secured it? He said: “You may be a service provider or a merchant, but I am really concerned on the way that websites are set up to do redirects. You’re relying on merchants to write secure code so your credit card details are not stolen, but as developers you have to demonstrate that you are up to speed.”
Pointing to PCI DSS requirements, Williams pointed out that there are five of the 12 requirements that cover software, and regarding version three, which features more emphasis on testing, he said this is not done properly.
“I am more confident in developers doing it properly than them demonstrating it. Requirement 6.3 says “Develop software applications in accordance with PCI DSS and based on industry best practices and incorporate information security throughout the software development life cycle”, but why is software development lifecycle so low? What is strong encryption? If you wrote an application last year, the chances are that it is out of date now.”
He also highlighted requirement 8 sections 3, 4 and 5, and requirement 10 sections 2, 3 and 5, as well as requirement 6.4 on “change processes for system components”.  Williams said that websites are often built and tested and, if they fail, you fix it. “You test again a year later, and the problems are back as the flaws are in the development system and not the code, so with a robust system for change control that shouldn’t happen,” he said.
“6.5 addresses common coding vulnerabilities, and training developers in secure coding techniques. Can you demonstrate that you do know secure programming? Do you develop applications within secure coding guidelines?”
Williams said that those doing it right were building security in, and asked how developers are being trained, and could you prove to a QSA that your developers have been trained? “The QSA should want to be convinced that you are doing things right, and they will also look for competence, such as did the developers do a course? Did you do continuous development cycle and maintain knowledge of security? Sometimes changes do need to occur quickly, but with design processes. Also ensure do not suffer from known vulnerabilities.”
In conclusion, Williams made
the point that in terms of secure applications and a QSA audit, it is about providing documentation that you have met that requirement, that procedures and policies being followed and that the people writing the applications are knowledgeable and up to date.
He said: “Where the problem comes in is on the evidence side, and if you demonstrate on an annual audit that good practice has occurred throughout the whole year, can or how will you demonstrate that your developers are following best practice?”
I attended a number of talks this year in the day that I spent at AppSec Europe, and I am glad to say I didn’t see a disappointing or bad talk. The reason for covering this in depth is because I thought the area was pretty unique and significant, and hopefully this advice should prove to be worthwhile to all of those lucky enough to face QSA audits.

Tags: application securityPCI DSSQSA
ShareTweet
Previous Post

AppSecEu: Two year CISO strategies enable better budget negotiation

Next Post

Public and private sector partnerships key to cyber crime fight, say BBA and NCCU

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol