This page was machine-translated and may differ from the original. View original
The PCI Security Standards Council Releases New Software Security Standards
New PCI Standard for Software Vendors
Promoting the development of secure SW solutions for next-generation payments.
It will replace the PA-DSS and its list, which expires in 2022.
The PCI Security Standards Council (PCI SSC) announced new requirements for the secure design and development of modern payment software on the 16th. 
PCI Security Standards Council
The PCI Secure Software Standard and the PCI Secure Lifecycle (Secure SLC) standard are part of the new PCI Software Security Framework, which includes a validation program for software vendors and their software products and a qualification program for assessors. The program will launch in late 2019.
“Innovation in payments is happening at an incredible pace,” said Troy Leach, PCI SSC Chief Technology Officer. “These advancements provide the industry with the opportunity to develop applications faster and more efficiently than ever before and design software for new platforms for payment acceptance.”
“The new PCI Secure Software Standard and PCI Secure SLC Standard support this evolution by providing developers with a dynamic way to demonstrate that their software can protect payment data in next-generation applications,” he added.
The PCI Software Security Standard addresses overall software resiliency for modern payment software beyond the scope of the Payment Application Data Security Standard (PA-DSS) for legacy payment software.
The PCI Secure Software Standard establishes security requirements and evaluation procedures to ensure that payment software adequately protects the integrity and confidentiality of payment transactions and data.
The PCI Security SLC standard establishes security requirements and assessment procedures to ensure that software vendors properly manage payment software throughout the software lifecycle.
This standard replaces the PA-DSS and its list, which expires in 2022. A gradual transition period will be provided for organizations that have invested in the PA-DSS.
The PCI Software Security Standard was developed with input from a dedicated task force of payment card industry participants. Additionally, PCI SSC participating organizations and assessors reviewed the standard and provided feedback and suggested alternatives through multiple request for comments (RFC) periods throughout the development process.
“We were pleased to review the final version of the PCI Secure Software Lifecycle Standard,” said Steve Lipner, Executive Director of the Software Assurance Forum for Excellence in Code (SAFECode), who served on the PCI Software Security Task Force. “This document clearly reflects software security best practices as required by the payment card industry and its associated certification processes, and aligns well with the principles and concepts of SAFECode’s Fundamental Practices for Secure Software Development.”
In particular, he emphasized, “I was satisfied with the fact that they focused on integrating security into the software development process rather than ensuring security through post-facto testing.”
The PCI Secure Software Standard, PCI Secure SLC Standard, and related FAQ documents, as well as glossaries of terms, abbreviations, and acronyms, are available for download from the website's Document Library.
Promoting the development of secure SW solutions for next-generation payments.
It will replace the PA-DSS and its list, which expires in 2022.
The PCI Security Standards Council (PCI SSC) announced new requirements for the secure design and development of modern payment software on the 16th.

PCI Security Standards Council
The PCI Secure Software Standard and the PCI Secure Lifecycle (Secure SLC) standard are part of the new PCI Software Security Framework, which includes a validation program for software vendors and their software products and a qualification program for assessors. The program will launch in late 2019.
“Innovation in payments is happening at an incredible pace,” said Troy Leach, PCI SSC Chief Technology Officer. “These advancements provide the industry with the opportunity to develop applications faster and more efficiently than ever before and design software for new platforms for payment acceptance.”
“The new PCI Secure Software Standard and PCI Secure SLC Standard support this evolution by providing developers with a dynamic way to demonstrate that their software can protect payment data in next-generation applications,” he added.
The PCI Software Security Standard addresses overall software resiliency for modern payment software beyond the scope of the Payment Application Data Security Standard (PA-DSS) for legacy payment software.
The PCI Secure Software Standard establishes security requirements and evaluation procedures to ensure that payment software adequately protects the integrity and confidentiality of payment transactions and data.
The PCI Security SLC standard establishes security requirements and assessment procedures to ensure that software vendors properly manage payment software throughout the software lifecycle.
This standard replaces the PA-DSS and its list, which expires in 2022. A gradual transition period will be provided for organizations that have invested in the PA-DSS.
The PCI Software Security Standard was developed with input from a dedicated task force of payment card industry participants. Additionally, PCI SSC participating organizations and assessors reviewed the standard and provided feedback and suggested alternatives through multiple request for comments (RFC) periods throughout the development process.
“We were pleased to review the final version of the PCI Secure Software Lifecycle Standard,” said Steve Lipner, Executive Director of the Software Assurance Forum for Excellence in Code (SAFECode), who served on the PCI Software Security Task Force. “This document clearly reflects software security best practices as required by the payment card industry and its associated certification processes, and aligns well with the principles and concepts of SAFECode’s Fundamental Practices for Secure Software Development.”
In particular, he emphasized, “I was satisfied with the fact that they focused on integrating security into the software development process rather than ensuring security through post-facto testing.”
The PCI Secure Software Standard, PCI Secure SLC Standard, and related FAQ documents, as well as glossaries of terms, abbreviations, and acronyms, are available for download from the website's Document Library.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)












