Regulation: Payment Card Industry Data Security Standard (PCI DSS) Flashcards
1
Q
If a company suffers from a breach of customer credit card records, under the terms of PCI DSS, what organization may choose to purse an investigation of this matter?
A
- bank
- PCI is enforced through contractual relationships between merchants and their banks
- law enforcement can be used for criminal investigations
2
Q
How often does PCI DSS require application vulnerability scans?
A
at least annually and after any change in the application
3
Q
What technology may be put in place that eliminates the PCI DSS requirement for recurring web vulnerability scans?
A
PCI DSS allows organizations to choose between performing annual web vulnerability assessment tests or installing a web application firewall
4
Q
What are the 6 major objectives of PCI/DSS?
A
- a secure network must be maintained in which transactions can be conducted
- cardholder information must be protected wherever it is stored
- systems should be protected against the activities of malicious hackers
- cardholder data should be protected physically as well as electronically
- networks must be constantly monitored and regularly tested
- a formal information security policy must be defined, maintained and followed
5
Q
A