What code review requirements exist in PCI DSS?
- A.Only review third-party code, an arrangement the standard blesses whenever the provider appears on a card brand registry, since registry listing substitutes for the customer's own due diligence and monitoring
- B.Only review code annually
- C.Code reviews are optional, because v4.0 measures patching solely against vendor end-of-life dates, meaning any still-supported product is considered adequately patched regardless of outstanding security updates
- D.Custom code must be reviewed prior to release to production to identify potential coding vulnerabilities, either through manual review or automated tools
Why D is correct
All custom code must be reviewed before production deployment to identify coding vulnerabilities, using either manual review or automated analysis tools.
Know someone studying for PCI DSS? Send them this one.