hi sc-l, My November column (which just went up today?!) is about following the spirit of PCI compliance versus checking the box. I even have something nice-ish to say about web app firewalls.
http://www.darkreading.com/document.asp?doc_id=140979&WT.svl=column1_1 For those of you involved in PCI compliance activities, how many have seen them spearhead real software security? How about box checking? I would love to see an informal poll. gem company www.cigital.com podcast www.cigital.com/silverbullet blog www.cigital.com/justiceleague book www.swsec.com _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________