1B: Acknowledge Compliance Requirements Flashcards
1.1 Compare and contrast governance, risk, and compliance reports.
Which standard specifies the controls that must be in place to securely handle credit card data?
Payment Card Industry Data Security Standard (PCI-DSS)
How many categories does the PCI-DSS standard use to describe what is required?
Six Categories
Of the four PCI-DSS levels, which level defines a merchant with over six million transactions a year?
Level 1
Of the four PCI-DSS levels, which level defines a merchant with one to six million transactions a year?
Level 2
Of the four PCI-DSS levels, which level defines a merchant with 20,000 to one million transactions a year?
Level 3
Of the four PCI-DSS levels, which level defines a small merchant with under 20,000 transactions a year?
Level 4
Of the four PCI-DSS levels, which level must have an external auditor perform the assessment by an approved Qualified Security Assessor (QSA)?
Level 1
Of the four PCI-DSS levels, which levels must complete a Report on Compliance (RoC)?
Level 1 and 2
Of the four PCI-DSS levels, which levels can either have an external auditor or submit a self-test that proves they are taking active steps to secure the infrastructure?
Levels 2-4
In 2018 the EU enacted this regulation which outlines specific requirements on how consumer data is protected.The law affects anyone who does business with residents of the EU and Britain. This comprehensive law focuses on the privacy of consumer data and, more importantly, gives consumers the ability to control how their data is handled.
General Data Protection Regulation (GDPR)
A law that was enacted in New York state in March 2020 to protect citizens data. The law requires companies to bolster their cybersecurity defense methods to prevent a data breach and protect consumer data.
Stop Hacks and Improve Electronic Data Security (SHIELD)
This law was enacted in 2020 and outlines specific guidelines on how to appropriately handle consumer data. To ensure that customer data is adequately protected, vendors should include PenTesting of all web applications, internal systems along with social engineering assessments.
California Consumer Privacy Act (CCPA)
A law that mandates rigorous requirements for anyone that deals with patient information.
Health Insurance Portability and Accountability Act (HIPPA)