Recently, Schellman & Company has become one of the first firms in the industry to offer PCI Software Security Framework (SSF) assessments as a Secure Software and a Secure SLC Assessor. As the newest application security framework published by the PCI SSC, the SSF provides an objectives-based approach to assessing the design, development, testing, and maintenance of software that handles payment card data.
The framework itself contains two standards:
- The Secure Software Lifecycle Standard – An interview and document-based assessment that focuses on software development and security practices.
- The Secure Software Standard – Application security testing by the assessor that requires code reviews, forensic analysis, and the use of static and dynamic code analysis tools.
PCI practice director Jacob Ansari says,
“After working with the PCI SSC for several years to help develop this framework, we’re happy to see the framework fully realized and look forward to working with our clients to comply with these standards.”
For information about the PCI SSF, please contact pci@schellman.com.
About the Author
More Content by Jacob Ansari