Why does PCI DSS reference the OWASP Top 10?
- A.OWASP is the only secure coding standard, because test data drawn from production is acceptable in development so long as the developers sign confidentiality agreements
- B.The OWASP Top 10 identifies the most critical web application security risks that applications must be protected against
- C.OWASP provides antivirus signatures, which Requirement 5.3.3 requires to scan removable electronic media automatically when such media is in use
- D.OWASP is a PCI DSS requirement
Why B is correct
PCI DSS requires protection against common vulnerabilities, and the OWASP Top 10 provides a widely accepted list of the most critical web application security risks.
Know someone studying for PCI DSS? Send them this one.