Conversation
🚀 Deploying Preview to Cloudflare 🚀Preview URL: https://dee-3623-client-side-pci-dss.previews.developers.cloudflare.com (commit 3d11432)This URL reflects your latest Preview deploymentPreview Deployments by commit
|
|
This pull request requires reviews from CODEOWNERS as it changes files that match the following patterns:
|
Review✅ No issues found in commit Code ReviewThis code review is in beta and may not always be helpful — use your judgment. No code review issues found. ConventionsNo convention issues found. Style Guide ReviewNo style-guide issues found. CommandsOnly codeowners can run commands. Post a comment with the command to trigger it.
|
|
Preview URL: https://3d11432e.preview.developers.cloudflare.com Files with changes (up to 15) |
DEE-3623
4890173 to
4a60052
Compare
DEE-3623 - Replace overclaiming "HTTP security headers and payment page content" with "monitored client-side resources on payment pages" - Replace "Alerts fire when scripts, connections, or cookies...change" with "Alerts can identify changes to monitored client-side resources" - Removes undocumented header/cookie-change alerting claim
xmflsct
left a comment
There was a problem hiding this comment.
We would need legal review especially on the requirements mapping part. The intention was the link to the white paper produced by a qualified assessor.
|
Closing won't do for now. |
Expands the client-side security PCI DSS documentation to meet requirements 6.4.3 and 11.6.1 introduced in PCI DSS v4.0.
DEE-3623
Changes
/client-side-security/reference/pci-dss/: expanded from a one-paragraph stub to a full requirements mapping table for PCI DSS v4.0 req 6.4.3 (payment page script management) and 11.6.1 (tamper detection), with setup steps and cross-links to the SSL PCI DSS guide and Cloudflare Trust Hub