Application Security for PCI DSS - FREE WEBINAR
Live video webinar / 60 mins / 28th August 08 / 11.30PST, 14.30 EST, 16.30 BST
How this webinar will help you
PCI DSS is a multidimensional standard developed with the intent of helping organizations protect customer data. The standard has evolved over the years, however, compliance to this standard continues to be a challenge for many organizations.
It becomes even more complex when it comes to interpretation and implementation of requirements corresponding to application security. In this session, we demystify the standard. We make it easier to understand the implementation aspects for compliance to application security requirements. We also focus on best practices for web application security from the perspective of secure development and testing.
The session will include answers to the following questions:
Agenda
- What are the requirements in the standard for application security?
- What should be done for compliance to Requirement 6 and Requirement 11?
- What is PA DSS and how does it support compliance?
- What are the practices that need to be incorporated in web application development for compliance to PCI DSS?
- What is the best approach for compliance towards the much debated requirement 6.6?
- What kind of tests should be conducted on web applications corresponding to requirement 11.3.2?
- What are the common vulnerabilities and solutions?
- What should be the approach to review custom code?
- What are the common issues and solutions around PCI compliance?
The panel
Vinod Vasudevan, CISSP, is the Director of Managed Risk Services at Paladion. He is the co-author of Enhancing Computer Security with S mart Technology, published by Auerbach. Prior to co-founding Paladion, Vinod worked with Microsoft. He wrote the chapter 'Application Security and ISO27001' in the book ‘Application Security in the ISO27001 Environment’.
Sangita Pakala,GCIH, is Head of Application Security Projects at Paladion. She has had experience on more than fifty application security projects. She is the lead author of the OWASP Application Security FAQ. Sangita’s work was presented at RSA Conference 2006 and ISACA Europe 2005. She wrote the chapter ‘Secure Development Lifecycle’.
