QSA Glosary Flashcards
AAA
Authentication, Authorization, and accounting
Account Data
Cardholder sensitive data to include account # and identifying data
Acquirer
The Merchant Bank, acquiring bank, or acquiring financial institution. Runs the payment acceptance
AOC
Attestation of compliance. A form that attests results of a self-assessment or Report on Compliance
AOV
attestation of validation
ASV
approved scanning vendor
Audit Log
the record of system activities. same as audit trail
BAU
business as usual. an organization’s normal routine
Card Skimmer
an physical swiper data capture device
CVV
Card verification code or value. CAV = JCB CVC = Mastercard CVV = Visa and Discover CSC = AmExp
CDE
cardholder data environment. People, processes, and technology that store, process, or transmit cardholder data or sensitive cardholder Au data
CERT
Carnegie-Mellon’s Computer Emergency Response Team
CIS
center for internet security. NFP enterprise w mission to help organizations reduce risk of business and e-commerce disruptions resulting from inadequate technical security controls
Compensation controls
Used to mitigate a risk that cannot be eliminated. Must: - Meet intent and rigor of original PCI DSS req
- Provide similar level of defense as original req
- be “above and beyond” other reqs
- be commensurate with the additional risk imposed by not adhering to original req
CVSS
Common Vulnerability Scoring System. an open standard used to convey severity of computer security and vulnerability
Dependency
in PA DSS world, hardware or software necessary for the payment application to meet PA DSS Reqs
DSS
Data Security Standard