Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Align PCI-DSS v3.2.1 to the "Finance and Insurance" Industry #317

Closed
2 tasks
cmlh opened this issue Dec 19, 2018 · 20 comments
Closed
2 tasks

Align PCI-DSS v3.2.1 to the "Finance and Insurance" Industry #317

cmlh opened this issue Dec 19, 2018 · 20 comments
Assignees
Labels
enhancement _5.0 - prep This needs to be addressed to prepare 5.0
Milestone

Comments

@cmlh
Copy link
Contributor

cmlh commented Dec 19, 2018

Both #78 and #77 are related issues which were discussed during the 3.0 milestone.

For the next release of ASVS can the reference to PCI-DSS in Appendix D be:

  • Aligned to L1, L2 and L3 within the Finance and Insurance Row of the Table on Page 11 of the ASVS v3.0.1 release?
  • Refreshed for PCI-DSS v3.2.1 and;

image

@vanderaj vanderaj self-assigned this Jan 1, 2019
@vanderaj vanderaj added this to the 4.0 milestone Feb 10, 2019
@vanderaj
Copy link
Member

@danielcuthbert @tghosth @jmanico @m8urnett - I do not have time for this this week, but Christian does bring up a good question. If none of us has time, could we at least push this for 4.1? I'm going to re-allocate to Daniel as he's in the banking sector, but I'm happy if anyone of us looks at it and sees if it can make 4.0

@vanderaj vanderaj modified the milestones: 4.0, After 4.0 Feb 18, 2019
@vanderaj vanderaj assigned danielcuthbert and unassigned vanderaj Feb 18, 2019
@vanderaj vanderaj modified the milestones: After 4.0, 4.1 Mar 6, 2019
@cmlh
Copy link
Contributor Author

cmlh commented Apr 6, 2019

@vanderaj Also the recent PCI Software Security Standard also adopted/based on the prior major release of ASVS v3 as suggested by https://twitter.com/oleggryb/status/1085613838597124096

@danielcuthbert I am willing to contribute the correlation of the PCI Software Security Standard to ASVS v4 for the next minor/major release?

@cmlh
Copy link
Contributor Author

cmlh commented Apr 23, 2019

@vanderaj Also the recent PCI Software Security Standard also adopted/based on the prior major release of ASVS v3 as suggested by https://twitter.com/oleggryb/status/1085613838597124096

@vanderaj The above was already addressed by @danielcuthbert within #378

@tghosth
Copy link
Collaborator

tghosth commented Oct 31, 2020

@cmlh is there any further effort needed here?

@cmlh
Copy link
Contributor Author

cmlh commented Oct 31, 2020

@tghosth

I am willing to contribute this provided I am given credit as a PR against ASVS v4.0.2?

It may also be worth considering to wait until PCI-DSS 4.0 is released in 2021?

image

@tghosth
Copy link
Collaborator

tghosth commented Nov 1, 2020

I think a mapping of PCI-DSS v3.2.1 to ASVS v4.0.2 would still be useful

@cmlh
Copy link
Contributor Author

cmlh commented Nov 1, 2020

@tghosth

There is around 18 months between the releases of ASVS 4.0.1 (March 2019) and 4.0.2 (October 2020).

PCI-DSS 4.0 is planned to be released by June 2020 at the latest or within 9 months.

If I integrate PCI-DSS v3.2.1 before June 2020 then will another release of ASVS be made?

@tghosth
Copy link
Collaborator

tghosth commented Nov 1, 2020

So from my perspective, we could issue a 4.0.3 faster if we had additional useful content. Can you describe in a little more detail what you would be preparing? Is it a simple mapping or is it more involved?

@cmlh
Copy link
Contributor Author

cmlh commented Nov 1, 2020

@tghosth The milestone for ASVS v4.1 is planned for 30 April 2021 and would take around a day or so to modify the table cited within this issue

@jmanico
Copy link
Member

jmanico commented Mar 12, 2021

We are pushing toward 4.1 so PR's in this are are appreciated.

@cmlh
Copy link
Contributor Author

cmlh commented Mar 14, 2021

PCI-DSS 4.0 is planned to be released by June 2020 at the latest or within 9 months.

PCI-DSS v4.0 has been postponed so I'll focus on PCI-DSS v3.2.1 for the ASVS 4.1 release and then open another issue for PCI-DSS v4.0.

@cmlh
Copy link
Contributor Author

cmlh commented Apr 29, 2021

The table within Appendix D has been removed since ASVS v3.0

image

PCI-DSS 3.5.1 has a brief mention within the last paragraph of page 8 within ASVS v4.0.2:

image

@cmlh
Copy link
Contributor Author

cmlh commented Apr 29, 2021

Below are the various requirements where OWASP is quoted within PCI DSS v3.2.1:

image

image

image

image

image

I have created the following markdown "task list" to track the PCI DSS v3.2.1 Requirements above:

  • 1.1.6
  • 2.2.3
  • 2.3
  • 4.1
  • 6.5

@danielcuthbert
Copy link
Collaborator

We are closing this for now as we feel that adding PCI-DSS requirements into the standard is a huge amount of work and the value of doing so will eat into efforts to make the ASVS standard better.

@cmlh
Copy link
Contributor Author

cmlh commented Jul 21, 2021

@danielcuthbert I believe the plan going forward was to fork ASVS for PCI-DSS Requirement 6.5 and the remaining [PCI-DSS Requirements] would be moved to the next minor release milestone of ASVS i.e. after ASVS 4.1 rather than take leadership at this point in time and align with the next release major 4.0 release of PCI DSS

@danielcuthbert
Copy link
Collaborator

If you wish to take this on, by all means. PCI has made it clear they have a standard and aren't open to sharing unless you are a paid member. I don't see what value forking ASVS to better meet PCI-DSS requirements would give us but happy to schooled here

@cmlh
Copy link
Contributor Author

cmlh commented Jul 21, 2021

Are you referring to https://www.pcisecuritystandards.org/get_involved/participating_organizations or something else as I've never been a member of PCI-SSC or had to pay a fee to access their documentation.

I do not believe that their continued reference to the OWASP Top Ten as "the OWASP Guide" in PCI-DSS is in the interest of application security.

@cmlh
Copy link
Contributor Author

cmlh commented Sep 9, 2021

@jmanico jmanico added _5.0 - prep This needs to be addressed to prepare 5.0 and removed question labels Dec 14, 2021
@jmanico jmanico self-assigned this Dec 14, 2021
@cmlh
Copy link
Contributor Author

cmlh commented Feb 27, 2022

@cmlh
Copy link
Contributor Author

cmlh commented Apr 1, 2022

Just marking a placeholder for the release of PCI-DSS 4.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement _5.0 - prep This needs to be addressed to prepare 5.0
Projects
None yet
Development

No branches or pull requests

5 participants