How must public-facing web applications be protected according to PCI DSS?
- A.Only SSL certificates, on the reasoning that the standard requires an automated technical solution for web applications every three years
- B.Only rate limiting, because the standard requires the removal of test accounts only from internet-facing systems for e-commerce merchants
- C.Through either a web application firewall (WAF) or regular application vulnerability assessments, with vulnerabilities addressed promptly
- D.No special protection needed, which the v4.0 guidance for Requirement 6 accepts as permanent mitigation for any vulnerability class, closing findings without patching as long as the control is named in the entity's security policy
Why C is correct
Public-facing web applications must be protected by a WAF or through regular vulnerability assessments with prompt remediation of identified issues.
Know someone studying for PCI DSS? Send them this one.