Skip to main content

πŸ’Ό 6.3 Develop internal and external software applications securely.

Description​

As follows:

  • In accordance with PCI DSS (for example, secure authentication and logging)
  • Based on industry standards and/or best practices.
  • Incorporating information security throughout the software-development life cycle.

This applies to all software developed internally as well as bespoke or custom software developed by a third party.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/06/02/01
  • Internal
    • ID: dec-c-ec8dbb6f

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 6.2.1 Bespoke and custom software are developed securely.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 6.2.1 Bespoke and custom software are developed securely.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 6.3.1 Remove development, test and/or custom application accounts, user IDs, and passwords before applications become active or are released to customers.
πŸ’Ό 6.3.2 Review custom code prior to release to production or customers in order to identify any potential coding vulnerability.