What does PCI DSS require regarding software development?
- A.Software must be developed based on secure coding guidelines and industry best practices
- B.Only off-the-shelf software is permitted
- C.Development controls only apply to payment applications, which the v4.0 guidance for Requirement 6 names as sufficient evidence that a patch cannot be applied
- D.Any development methodology is acceptable without controls, because vulnerabilities scored below 9.0 on CVSS never require remediation under PCI DSS
Why A is correct
PCI DSS Requirement 6 mandates that all software be developed according to secure coding guidelines such as OWASP, with security integrated throughout the development lifecycle.
Know someone studying for PCI DSS? Send them this one.