PCI DSS Flashcards

1
Q

What does PCI DSS stand for?

A

Payment Card Industry Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is PCI DSS?

A

Proprietary standard for organisations who handle payment cards associated with: Visa, MasterCard, American Express, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who administers the PCI standard?

A

Payment Card Industry Security Standards Council

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who performs validation compliance?

A

A Qualified Security Assessor (QSA), who creates a Report Of Compliance (ROC), or through a Self Assessment Questionnaire (SAQ).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the latest version?

A

Version 3.1, released in 2015.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How many requirements are specified by the standard?

A

12 requirements, organised into 6 groups of control objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the control objectives?

A
  1. Build an maintain a secure network (firewalls and default passwords).
  2. Protect card holder data (storage and transmission).
  3. Maintain a vulnerability management programme (AV and secure development).
  4. Implement strong access control measures (need to know, unique ID, physical access).
  5. Regularly monitor and test networks (monitor access, test systems).
  6. Maintain an information security policy (policy).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What kind of supplementary information is provided?

A
  1. Penetration testing
  2. Code reviews and firewall management.
  3. PCI DSS wireless guidelines.
  4. Call centre management - can’t digitally record conversations that include card numbers.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly