<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Secure Your Application &#8211; PCI DSS Specifications</title>
	<atom:link href="http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/feed" rel="self" type="application/rss+xml" />
	<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications</link>
	<description>The opposite of every great idea is another great idea</description>
	<lastBuildDate>Tue, 24 Jan 2012 10:54:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: David Cooke</title>
		<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/comment-page-1#comment-404</link>
		<dc:creator>David Cooke</dc:creator>
		<pubDate>Tue, 02 Jun 2009 13:23:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.simonwhatley.co.uk/?p=1785#comment-404</guid>
		<description>Brilliant and very informative write up. Although we don&#039;t currently store any credit card data we are just about to undergo a pen test and are currently going though a process of re-evaluating all our applications and infrastructure so this post has come in very handy indeed.

Just one note that in Application.cfc, scriptProtect should be set to &quot;All&quot;, &quot;None&quot; or a comma delimited list of variable scopes. It&#039;s also an application wide setting and not a variable.</description>
		<content:encoded><![CDATA[<p>Brilliant and very informative write up. Although we don&#8217;t currently store any credit card data we are just about to undergo a pen test and are currently going though a process of re-evaluating all our applications and infrastructure so this post has come in very handy indeed.</p>
<p>Just one note that in Application.cfc, scriptProtect should be set to &#8220;All&#8221;, &#8220;None&#8221; or a comma delimited list of variable scopes. It&#8217;s also an application wide setting and not a variable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry Ho</title>
		<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/comment-page-1#comment-403</link>
		<dc:creator>Henry Ho</dc:creator>
		<pubDate>Mon, 26 Jan 2009 18:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.simonwhatley.co.uk/?p=1785#comment-403</guid>
		<description>Thank you very much for the comprehensive list.

Have you had an CF app approved by PCI DSS before?</description>
		<content:encoded><![CDATA[<p>Thank you very much for the comprehensive list.</p>
<p>Have you had an CF app approved by PCI DSS before?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RyanTJ</title>
		<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/comment-page-1#comment-402</link>
		<dc:creator>RyanTJ</dc:creator>
		<pubDate>Mon, 26 Jan 2009 15:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.simonwhatley.co.uk/?p=1785#comment-402</guid>
		<description>I&#039;d also add: •	Do not identify if a username or email address is already in use with out validating other fields first and using something like CAPTCA to prevent automated attacks.</description>
		<content:encoded><![CDATA[<p>I&#8217;d also add: •	Do not identify if a username or email address is already in use with out validating other fields first and using something like CAPTCA to prevent automated attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon</title>
		<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/comment-page-1#comment-401</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Mon, 26 Jan 2009 13:11:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.simonwhatley.co.uk/?p=1785#comment-401</guid>
		<description>@glyn I would suggest that since your client is storing bank information, it is important that they hold it in a secure way. Implementing PCI DSS will certainly help, but they should refer to their bank for specific guidelines if they have any doubts.</description>
		<content:encoded><![CDATA[<p>@glyn I would suggest that since your client is storing bank information, it is important that they hold it in a secure way. Implementing PCI DSS will certainly help, but they should refer to their bank for specific guidelines if they have any doubts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glyn Jackson</title>
		<link>http://www.simonwhatley.co.uk/secure-your-application-pci-dss-specifications/comment-page-1#comment-400</link>
		<dc:creator>Glyn Jackson</dc:creator>
		<pubDate>Mon, 26 Jan 2009 12:59:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.simonwhatley.co.uk/?p=1785#comment-400</guid>
		<description>Thanks for this, very well written. I was just sending an email to a client on this subject. They are storing bank account information and not card details, does this mean they get away with not doing any of this?</description>
		<content:encoded><![CDATA[<p>Thanks for this, very well written. I was just sending an email to a client on this subject. They are storing bank account information and not card details, does this mean they get away with not doing any of this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

