Glossary Flashcards

1
Q

Acquirer

A

Merchant Bank
Acquiring Bank
Acquiring Financial Institution

Entity,typically a financial institution, that processes payment card transactions for merchants and is defined by a payment brand as an acquirer.

Acquirer are subject to payment brand rules and procedures regarding merchant compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Account Number

A

Primary ACcount Number (PAN)

16 Digit
or
15 Digit (AMERICAN EXPRESS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AOC (Attestation of Compliance)

A

The AOC is a form for merchants and service providers to attest to the results of a PCI DSS assessment, as documented in the Self-Assessment Questionnaire or Report on Compliance.

Quick Summary of the ROC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ASV (Approved Scanning Vendor)
(Req 11)

A

Company approved by the PCI SSC to conduct external vulnerability scanning service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Card Skimmer
(Req 9.9)

A

A physical device, often attached to a legitimate card-reading device, designed to illegitimately capture and/or store the information from a payment card.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Card Verification Code or Value

A

Card Validation Code or Value or Card Security Code.

  1. Magnetic-stripe data
  2. printed security feature
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Card holder

A

Non-consumer or consumer customer to whom a payment card is issued to or any individual authorized to use the payment card.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Cardholder Data

A

Full PAN plus cardholder name, expiration date and/or service code.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CDE (Cardholder Data Environment)

A

The people, process, and technology that store process, or transmits cardholder data or sensitive authentication data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Insecure Protocol/Service Port
(Req 2)

A

A protocol, service, port that Introduce security concern due to lack of controls over confidentiality and/or integrity.

These security concerns include service, protocols, or ports that transmits data or authentication credentials (password/passphrase) in clear-text over the Internet, or easily allow for exploitations by defaults or if misconfigured.

EX: FTP, Telnet, POP3, IMAP, and SNMP v1 adn v2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Masking

A

In the context of PCI DSS, it is a method of concealing a segment of data when displayed or printed.

Masking is used when there is no business requirement to view the entire PAN.

Masking relates to protection of PAN when displayed or printed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Payment Processor

A

Sometimes referred to as payment gateway or payment service provider.

Entity engaged by a merchant or other entity to handle payment card transactions on their behalf.

While payment processors typically provide acquiring services, payment processors are not considered acquires unless defined as such by a payment card brand.

EX: website > Stripe , Paypal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ROC (Report on Compliance)
“ROCK”

A

Report documenting detailed results from an entity PCI DSS assessment.

Should NEVER be shared that’s what the AOC is for!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Sensitive Authentication Data

SAD data!

A

Security-related information (included but not limited to card validation codes/values, full track data (from magnetic stripe or equivalent on a chips), PINs, and PIN blocks) used to authenticate cardholders and /or authorize payment card transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Strong Cryptography

A

Cryptography based on industry-tested and accepted algorithms, along with key lengths that provide minimum of 112-bits of effective key strength and proper key-management practices.

Cryptography is a method to protect data and includes both encryption (which is reversible) and hashing (which is “one way”; that is, not reversible) .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly