PCI DSS
PCI DSS 4.0.1 and Requirements 6.4.3 and 11.6.1: What Changed for Payment Page Scripts
For over a decade, PCI DSS treated the browser as someone else's problem. Card data was protected in transit and at rest on the server, but the code actually running in the customer's browser — where card details are typed in — sat largely outside the standard'