Martin and a bunch of others have written about the recent clarifications around section 6.6 and 11.3 of the PCI DSS. Jim Carr over at SC Magazine ran an article on it today that he interviewed me for. While I am not the PCI expert Martin is, I was happy to contribute my 2 cents (ain't I always).
Anyway, sounds to me like these new clarifications are going to wind up with a lot of web application firewalls being sold. Here at StillSecure we are thinking about some ways to take those to the next level as well. Hopefully we can announce something soon on this. Overall, just another indication that right or wrong, compliance is driving a lot of the spending in security today.





