Modelo para cumplimiento de PCI DSS en interfaces web de pago sobre Cloud Computing
Fecha
Autores
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
This research explores the integration between the prioritized approach to PCI DSS compliance along with the practices defined in the OWASP DevSecOps Maturity Model (DSOMM). For this purpose, a continuous compliance model is proposed that relates the PCI DSS requirements that would be applicable to a web payment interface on cloud computing with the DevSecOps phases, in this way, compliance efforts are focused on the entire life cycle of the software development in specific parts, thus guaranteeing that PCI DSS compliance occurs in all phases where applicable and occurs continuously. In the proposed model, in addition to establishing the integration between the prioritized approach of PCI DSS and DevSecOps, the standard of compliance evidence will also be established for each of the DevSecOps phases, and the processes and procedures for the delivery and review of the evidence. For the final validation of the proposed model, it was qualitatively compared against the implementation of the prioritized approach to PCI DSS compliance without integration with DevSecOps or compliance evidence standard or defined processes or procedures for the delivery and review of evidence, resulting that the proposed model provides the robust cybersecurity expected by achieving compliance through: Equitable distribution of all compliance efforts applicable to all phases of DevSecOps, consolidation of a better compliance program compared to the application of the prioritized approach alone of PCI DSS, the correct segregation of roles in compliance that allows the unification of joint compliance efforts, and the reduction of human error in compliance since the orientation towards DevSecOps provides automations.