The PCI Council’s response regarding a monitoring-only WAF (Req. 6.6, PCI DSS 3.0)
On July I wrote a blog post about the modified Requirement 6.6 in PCI DSS 3.0. I am not going into the details again, it’s sufficient to say that the new standard allows to operate a WAF in monitoring only mode without blocking requests: 6.6 For public-facing web applications, ensure that either of the following … [Read more…]
