PCI DSS Requirement 6: Develop and Maintain Secure Systems
Blog post from Basis Theory
PCI DSS Requirement 6 establishes controls for developing and maintaining secure systems and software to protect account data from vulnerabilities, attacks, and insecure changes. Its five sections require organizations to document security policies and responsibilities, embed secure coding practices throughout custom software development, train developers annually, conduct independent code reviews, and use techniques that address common attack types. Organizations must identify, rank, track, and remediate vulnerabilities in custom and third-party software, maintain component inventories, install critical patches within one month, and apply other updates within risk-appropriate timeframes. Public-facing applications must undergo periodic security assessments or be protected by automated web-attack defenses, while payment-page scripts require authorization, integrity verification, and documented inventories. Secure change management includes approval, security-impact analysis, testing, rollback procedures, separation of production and pre-production environments, and restrictions on live cardholder data and test accounts. The text also presents Basis Theory as a PCI Level 1-compliant provider that can help customers reduce their PCI scope by securing card data within its assessed cardholder data environment.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.