2025Q3 PCI DSS Workshop
A workshop on three application-layer requirements in PCI DSS v4.0.1: secure SDLC code review, payment page script management, and change and tamper detection.

PCI DSS v4.0.1 introduces three critical new application-layer requirements:
- 6.3.2 Secure SDLC & Code Review
- 6.4.3 Payment Page Script Management
- 11.6.1 Change and Tamper Detection
These address client-side attacks (e.g., Magecart) and strengthen compliance defenses from development to the browser endpoint.
This session features Dr. Ding Sun, International Open Source Security Expert at Black Duck, who will share first-hand practical experience from Singapore. Combining requirement interpretation with technical implementation, he will help teams upgrade compliance and security in one step.
- 🔍 Requirement Breakdown: key high-risk application-layer controls in PCI DSS v4.0.1
- 🛠️ Technical Implementation: Secure SDLC integration, payment page script control, and change/tamper detection
- 💡 Risk Mitigation: protection strategies against client-side attacks (e.g., Magecart)
- 🌏 Global Insights: best practices from Black Duck's international expert
Highlighted PCI DSS Requirements
Req. 6.3.2 – 🛠️ Secure SDLC Integration
Implement security checkpoints across requirements, design, development, testing, and deployment — "prevention is better than cure."
Req. 6.4.3 – 🧩 Payment Page Security Strategy
Establish robust script management and authorization processes to block client-side data theft.
Req. 11.6.1 – 🕵️ Change and Tamper Detection
Continuously monitor payment page and data transmission integrity to quickly detect and respond to anomalies.
Speaker
Dr. Sun Ding – Senior Consultant, Black Duck Solutions
- Extensive international experience in cybersecurity and compliance
- Specializes in open-source security, application vulnerability management, and compliance strategy implementation
About Black Duck: Black Duck Software provides application security testing solutions for open-source software security and compliance, helping enterprises manage and reduce risks in both cloud and on-premises deployments — enhancing software trustworthiness and business competitiveness.
- #PCI DSS
- #Compliance
- #Cybersecurity
- #Script
- #HTTPHeader
- #SBOM
- #CSP
- #SRI
- #ComponentScan
Event Details
- 📅 Time: Thursday, 2025-08-28 | 2:00 – 4:30 PM
- 📍 Location: Secure Vectors, Taipei Office (MRT Nanjing Fuxing Station Exit 8 or Songjiang Nanjing Station Exit 6)
- Seats are limited — don't miss out!
