Payment Card Industry Data Security Standard (PCI DSS): mandates that retailers ensure that Web-facing applications are protected against known attacks by applying either of the following two methods:
1. Have all custom application code reviewed for vulnerabilities by an application security firm.
2. Install an application layer firewall in front of Web-facing applications. Each application will have its own firewall to protect against intrusions and malware.