PCI SSC publishes Secure Software Standard – Sensitive Asset Identification
Original title: Secure Software Standard – Sensitive Asset Identification
PCI SSC has published the Secure Software Standard – Sensitive Asset Identification, a new standard for secure software development. This standard provides requirements for identifying and protecting sensitive assets throughout the software development lifecycle. Organizations developing payment card software or building systems for the payment card industry must implement these controls to meet evolving security expectations.
What changed
- New standard published addressing sensitive asset identification in secure software development
- Requirements for identifying and documenting sensitive assets during the software development lifecycle
- Controls and practices for protecting identified sensitive assets in payment card software
- Alignment with broader PCI SSC Secure Software development framework and industry best practices
Who is affected
Software developers, payment processors, acquiring and issuing banks, payment service providers, and any organization developing or maintaining software for payment card processing systems globally
- Language
- EN