30 Day Trial

The Fastest and Easiest Way to Get Moving on Requirements 6.4.3 and 11.6.1

Source Defense is proud to offer a 30-day trial to get you moving on addressing the strict new requirements for website security in PCI DSS 4.0. Available for Merchants as a management solution and to help QSAs assess compliance, the Source Defense lets you assess, monitor and report on compliance with all aspects of 6.4.3 and 11.6.1.

Make a complex set of requirements easy for all involved!

  • Effortlessly gain full compliance visibility
  • Quickly identify any gaps and drive remediation
  • Manage your posture with a simple to use dashboard
  • One-click reporting to share findings and enrich broader compliance activities
  • Easily integrate findings into your monthly, quarterly and yearly PCI processes
  • Streamline management of these requirements with little to no workload

Register today and easily address these complex new requirements and more!

  • Inventory:  get an inventory of every script running on website payment pages, including a method for monitoring and tracking additions (required under 6.4.3)
  • Justification: gain the ability to seek, document and manage justification of any scripts on website payment pages (required under 6.4.3)
  • Integrity Monitoring: address the stringent requirements for integrity monitoring of HTTPS header and scripts found on website payment pages
    • Offered weekly for the first 30 days
    • Scaled back to monthly thereafter with the ability to upgrade for a fee
  • Alerting: alert on suspicious and malicious activity found on website payment pages (required under 11.6.1)
  • Blocking: feed alerts to your security team or automatically block all suspicious and malicious activity by upgrading (required under 11.6.1)

Frequently Asked Questions

How long does the solution take to integrate?

Integration is very simple. It requires the simple copy/paste of two lines of JS to your site’s head section.

Our experts and machine learning can be leveraged to configure the system for you. Should custom configuration be required the administration console provides these tools.

The system is designed to be low touch. The only time you will need to manage it, is when you integrate a new third party to your site.

The Source Defense solution is architected for deployment and administration simplicity. Although there is a small synchronous component to the solution, that adds approximately 100ms of latency. The solution then operates to isolate introduced 3rd party latency from your content ensuring that the impact of latency from loading multiple 3rd party JavaScript integrations are alleviated. Most deployment recognize a latency and stability improvement when deploying the Source Defense solution.

Every website today that operates with 3rd party JavaScript is vulnerable to this attack vector. Today, it is difficult to find a website that doesn’t include multiple dozens of 3rd party JavaScript integrations. In fact, over 50% of all page requests are 3rdparty calls. In general, the more 3rd party scripts you use, the higher your risk exposure will be.

Yes, the system is built for scale, running of a strong CDN with several redundancies.

Source Defense
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.