"Implementing Deny All Web Application Firewall was the most efficient and cost effective solution to comply with the PCI DSS Standard and to secure our growing number of web applications. Deny All WAF solution was the easiest to deploy, configure and replicate of the solutions we looked at. "

 

Petri Vuontela, Director, Customer systems at Aktia

Want to make your Web Applications PCI DSS-Compliant ?

 

Join our PCI DSS Expert for an educational webinar about WAF benefits and customer best practices.

About PCI DSS

Any type of company in the business of processing, storing and transmitting cardholder and transaction data (e.g. merchants, banks, processors, and point-of-sale vendors) must comply with PCI DSS in order to maintain membership status and be authorized to accept credit cards.

 

Lack of compliance may lead to penalty fines (up to $500,000 per data loss), restrictions and even permanent exclusion from card acceptance programs.
By extension, the PCI DSS standard is considered by many businesses as the standard by which to ensure tight security of their IT infrastructure.

 

The PCI Security Standards Council was formed by the major payment card companies including American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa to build an open global forum in which all participants can provide input into the ongoing development, enhancement, and dissemination of the PCI Data Security Standard (DSS) and other standards that increase payment data security.

 

The goal of PCI DSS is to enhance payment account data security best practices to protect sensitive cardholder information, reduce fraud and identify security issues that could be exploited by malicious users.

 

PCI DSS standard 1.1 (issued in September 2006) adds a major requirement (requirement 6.6): protecting Web Applications either by auditing their code or by deploying a Web application firewall.

 

This requirement is mandatory as of 30 June 2008 in order to obtain PCI DSS compliance.

 

 

DENY ALL, THE WEB APPLICATION SECURITY SPECIALIST

As the leading Web Application Firewall vendor in Europe, Deny All has unique expertise in securing dynamic and rapidly-changing applications. The company has helped large organizations comply with PCI DSS requirements and enhance their e-business with a global application delivery including proactive Web application Security, Web infrastructure acceleration and architecture simplification.

 

 

 

PCI DSS REQUIREMENTS

Implement Strong Access Control Measures

Requirement 7
Restrict access to cardholder data by business need-to-know.

Requirement 8
Assign a unique ID to each person with computer access.

Requirement 9
Restrict physical access to cardholder data.

 

Regularly Monitor and Test Networks

Requirement 10
Track and monitor all access to network resources and cardholder data.

Requirement 11
Regularly test security systems and processes.

 

Maintain an Information Security Policy

Requirement 12
Maintain a policy that addresses information security.

Build and Maintain a Secure Network

Requirement 1
Install and maintain a firewall configuration to protect cardholder data.

Requirement 2
Do not use vendor-supplied defaults for system passwords and other security parameters.

 

Protect Cardholder Data

Requirement 3
Protect stored cardholder data.

Requirement 4
Encrypt transmission of cardholder data across open public networks

 

Maintain a Vulnerability Management Program

Requirement 5
Use and regularly update anti-virus software.

Requirement 6
Develop and maintain secure systems and applications.

 

Learn more about PCI-DSS