Module 5 - Payment Card Industry (PCI) Data Security Standards (DSS) Flashcards

1
Q

what is PCIDSS

A

Payment Card Industry Data Security Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

why was PCIDSS developed

A

The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage and enhance payment card account data security and facilitate the broad adoption of consistent data security measures globally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what are 2 items that PCIDSS provide

A
  • PCI DSS provides a baseline of technical and operational requirements designed to protect account data
  • Consists of the 12 PCI DSS principal requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what else can PCIDSS be used for

A

to protect against threats and secure other elements in
the payment ecosystem.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

who is PCIDSS intended for

A
  • PCI DSS is intended for all entities that store, process, or
    transmit CHD and/or SAD or could impact the security of
    the CDE.
  • includes all entities involved in payment card account processing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is considered CHD with regards to PCIDSS

A
  • Primary Account Number (PAN)
  • Cardholder Name
  • Expiration Date
  • Service Code
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what does CHD stand for when referencing PCIDSS

A

Cardholder data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what does SAD stand for when talking abut PCIDSS

A

Sensitive authentication Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is considered SAD when talking about PCIDSS

A
  • Full track data (magnetic-stripe data or equivalent on a chip)
  • Card verification code
  • PINs/PIN blocks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what does PAN mean with PCIDSS

A

Primary Account Number

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

IF PAN is stored with other elements of CHD, what is required
1. all information is rendered unreadable
2. only the CHD is rendered unreadable
3. only the PAN is rendered unreadable
4. this does not fit a requirement

A

only the PAN is required to be rendeared unreadable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

thoughts about wireless networks being part of the PCIDSS network

A
  1. PCI DSS requirements and testing procedures for securing wireless environments apply and must be performed.
  2. Rogue wireless detection must be performed per PCI DSS Requirement 11.2.1 even when wireless is not used within the CDE and the entity has a policy that prohibits the use of wireless technology within its environment.
  3. This is because of the ease with which a wireless access point can be attached to a network, the difficulty in detecting its presence, and the increased risk presented
  4. Before wireless technology is implemented, an entity should carefully evaluate the need for the technology against the risk
  5. Consider deploying wireless technology only for non-sensitive data transmission
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are the 3 steps to testing PCIDSS

A
  1. Examine
  2. Observe
  3. Interview
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what is in the examine testing phase of PCIDSS testing

A

The assessor critically evaluates data evidence. Common examples include documents (electronic or physical), screenshots, configuration files, audit logs, and data files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what is in the observe phase of PCIDSS testing

A

The assessor watches an action or views something in the environment. - Examples: include personnel performing a task or process, system components performing a function

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is in the interview phase of PCIDSS testing

A

The assessor converses with individual personnel. Interviews might include confirmation of whether an activity is performed, descriptions of how an activity is performed, do personnel have the knowledge and understanding