This achievement qualifies ControlCase to assess vendors’ software lifecycle management practices and payment software in accordance with the PCI Software Security Framework.
Fairfax, VA USA – June 2020
ControlCase, a leading provider of IT Security Certifications, Cybersecurity and Continuous Compliance Services, announced its latest achievement: PCI Software Security Framework Assessor Company. This achievement qualifies ControlCase to assess vendors’ software lifecycle management practices and certify vendors’ payment software products in accordance with the PCI Software Security Framework.
The PCI Software Security Framework (SSF) is a collection of standards and programs for the secure design, development, and maintenance of payment software. The PCI Secure SLC Standard provides a baseline of requirements with corresponding assessment procedures and guidance to help payment software vendors design, develop, and maintain secure payment software throughout the software lifecycle. The set of security requirements and associated test procedures aim to ensure payment software adequately protects the integrity and confidentiality of payment transactions and data. The PCI Secure Software Standard replaces PA DSS which will be retired in October 2022.
“This is another proud moment for us… the program provides a continuous compliance and security solution for software vendors to efficiently manage and update their products,” said Biju John, Partner, Payment Product Group at ControlCase. “The program also helps software vendors demonstrate that their software supports or compliments client’s PCI DSS compliance.”
The ControlCase methodology for providing the assessments for the PCI Secure SLC Standard and the PCI Secure Software Standard is complimented by the company’s partnership approach to assessments – projects begin with a thorough scoping and gap analysis phase followed by remediation support and final assessment phase. The service is also supported by smart technology for security testing and a secure portal for evidence collection.