PCI Secure Software Lifecycle Standard
E723414
The PCI Secure Software Lifecycle Standard is a PCI Security Standards Council framework that defines security requirements and best practices for developing and maintaining payment software securely throughout its entire lifecycle.
Observed surface forms (1)
| Surface form | Occurrences |
|---|---|
| PCI Secure Software Standard | 1 |
Statements (49)
| Predicate | Object |
|---|---|
| instanceOf |
PCI SSC standard
ⓘ
security standard ⓘ software lifecycle framework ⓘ |
| appliesTo |
organizations developing payment software in‑house
ⓘ
payment application developers ⓘ software vendors ⓘ |
| domain |
payment security
ⓘ
software security ⓘ |
| encourages |
continuous improvement of software security practices
ⓘ
integration of security into software development lifecycle ⓘ |
| focus |
secure payment software lifecycle
ⓘ
secure software development practices ⓘ secure software maintenance practices ⓘ |
| fullName | PCI Secure Software Lifecycle Standard NERFINISHED ⓘ |
| geographicScope | global ⓘ |
| goal |
improve security of payment transactions
ⓘ
support compliance with PCI payment security objectives ⓘ |
| governingBody | PCI Security Standards Council NERFINISHED ⓘ |
| includes |
requirements for documentation and evidence of secure processes
ⓘ
requirements for governance of software security ⓘ requirements for patch and update management ⓘ requirements for secure coding ⓘ requirements for secure software design ⓘ requirements for software testing and validation ⓘ requirements for vulnerability management in software ⓘ |
| lifecycleCoverage |
deployment phase
ⓘ
design phase ⓘ development phase ⓘ maintenance phase ⓘ retirement phase ⓘ testing phase ⓘ |
| objective |
define security requirements for payment software development
ⓘ
promote secure coding practices for payment software ⓘ reduce vulnerabilities in payment software ⓘ support ongoing security for in‑production software ⓘ support secure software change management ⓘ support secure software release processes ⓘ |
| partOf | PCI Software Security Framework NERFINISHED ⓘ |
| publisher | PCI Security Standards Council NERFINISHED ⓘ |
| relatedTo |
PCI Secure Software Standard
NERFINISHED
ⓘ
PCI Software Security Framework NERFINISHED ⓘ |
| riskAddressed |
data breaches involving payment data
ⓘ
exploitation of insecure software changes ⓘ software vulnerabilities in payment applications ⓘ |
| scope |
payment software
ⓘ
software lifecycle ⓘ |
| shortName | PCI Secure SLC Standard NERFINISHED ⓘ |
| targetEnvironment | payment processing environments ⓘ |
| typeOfRequirement | industry standard ⓘ |
Referenced by (3)
Full triples — surface form annotated when it differs from this entity's canonical label.
Payment Application Data Security Standard
→
supersededBy
→
PCI Secure Software Lifecycle Standard
ⓘ
this entity surface form:
PCI Secure Software Standard