LinkedIn Tag
Upcoming Webinar: How to Pass PCI DSS 6.4.3 & 11.6.1 (cside x BARR Advisory)

Why doesn't a Content Security Policy (CSP) make us PCI compliant?

Requirements 6.4.3 and 11.6.1 of PCI DSS mandate scripts and HTTP headers to be monitored for changes. A Content Security Policy can only control the sources from where scripts are fetched. It has no view inside the script payload, hence it cannot spot changes that are required to meet PCI DSS demands.

¿Tienes preguntas?
Obtén respuestas de nuestros expertos