PABP 1.4 与 PA-DSS - 我们需要升级吗?
我们的应用程序已获得认证,并位于经过认证的 PABP 合规应用程序列表中。我们获得了最新的 PABP 1.4 认证。现在,PA-DSS 是新事物。是从 PABP 1.4 自动升级到 PA-DSS 还是需要重新审核?
Our applications are certified and on the list of certified PABP compliant applications. We were certified with the latest PABP 1.4. Now, PA-DSS is the new kid on the block. Is it an automatic upgrade to PA-DSS from PABP 1.4 or do we have to be re-audited?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
我相信他们是一个“遗留例外”类型的交易,只要您没有发布新版本,就可以让您继续遵守 PABP。不过您需要询问审计员才能确定。
一般来说,如果您刚刚完成认证,那么直到明年您都不需要做任何事情。届时,如果您发布了该软件的新版本,PA-DSS 可能会适用。
我大量开发的一个应用程序已经一年没有发布主要或次要版本了。由于我们只对其进行了修补,因此我们能够维持当前的 PABP 认证,而无需重新审核。这可能存在一些特殊情况,因此不要指望这是真的,除非审核员告诉您他们将为您提交新的 ROC。
I believe their is a "legacy exception" type deal that will allow you to stay under PABP as long as you haven't released a new version. Though you'll need to ask an auditor to be sure.
Generally if you've just finished certification, you don't need to do anything until the next year. At that point PA-DSS will likely apply if you've released a new version of the software.
An application I work heavily on has not had a major or minor release for a year. Since we only patched it, we were able to maintain our current PABP certification without a re-audit. There may have been some special circumstances with this, so don't count on this to be true unless an auditor tells you that they'll submit a new ROC for you.