Re: [SC-L] darkreading: PCI, web app firewalls, and software security

2007-12-13 Thread Pete Werner
Thanks for this, many interesting points. Many of them, such of quality of auditors and the vagueness of requirements/specifications are structural issues present in all industries that will never go away. There's never enough good people. If you're a shit hot accountant you're going to be off maki

Re: [SC-L] darkreading: PCI, web app firewalls, and software security

2007-12-13 Thread Gary McGraw
An interested sc-l reader who wishes to remain anonymous responded by mail to my PCI article. Here is what the reader had to say (posted with permission). gem = I have been involved in some of the PCI efforts here at my company. There's not much that my company would probably all