Certified Cloud Security Professional (CCSP)Cloud Application SecurityMedium
A company is developing a cloud application that processes payment card data. To achieve PCI DSS compliance requirement 6.5, which mandates addressing common coding vulnerabilities, the development team must integrate specific security practices into their software development lifecycle. Which of the following best satisfies this requirement?
- AEnsuring all cloud infrastructure components are patched within 24 hours of vulnerability disclosure.
- BConducting annual external penetration tests on the production environment.
- CAdopting secure coding guidelines and performing regular code reviews for vulnerabilities.
- DImplementing end-to-end encryption for all data in transit.
Show answer & explanationAnswer & explanation
Correct answer: C. Adopting secure coding guidelines and performing regular code reviews for vulnerabilities.
PCI DSS Requirement 6.5 specifically focuses on addressing common coding vulnerabilities. Adopting secure coding guidelines and conducting regular code reviews directly target the prevention and detection of these vulnerabilities in the application's source code.
Why the other options are wrong
- A. Patching infrastructure is vital for compliance (6.1, 6.2) but pertains to the underlying infrastructure, not directly to the application's *custom code* vulnerabilities as required by 6.5.
- B. Annual penetration tests are required by PCI DSS (11.3) but are a post-development activity and don't directly address the *coding* vulnerabilities during development.
- D. End-to-end encryption is crucial for data protection but is covered by other PCI DSS requirements (e.g., 4.1) and doesn't directly address *coding* vulnerabilities.
PCI DSS Requirement 6.5
A PCI DSS requirement mandating that applications be developed securely by addressing common coding vulnerabilities and preventing common attack methods.
- Focuses on application-layer security.
- Requires secure coding practices and vulnerability remediation.
- Often aligns with OWASP Top 10.
Memory trick: PCI 6.5: 'Secure Code' is the 'Golden Rule' for apps.