Low New document global

PCI SSC publishes Secure Software Standard – Sensitive Asset Identification

Original title: Secure Software Standard – Sensitive Asset Identification

PCI SSC has published the Secure Software Standard – Sensitive Asset Identification, a new standard for secure software development. This standard provides requirements for identifying and protecting sensitive assets throughout the software development lifecycle. Organizations developing payment card software or building systems for the payment card industry must implement these controls to meet evolving security expectations.

What changed

  • New standard published addressing sensitive asset identification in secure software development
  • Requirements for identifying and documenting sensitive assets during the software development lifecycle
  • Controls and practices for protecting identified sensitive assets in payment card software
  • Alignment with broader PCI SSC Secure Software development framework and industry best practices

Who is affected

Software developers, payment processors, acquiring and issuing banks, payment service providers, and any organization developing or maintaining software for payment card processing systems globally

Language
EN

Frameworks

PCI DSS

Open the original source