Regulation: Payment Card Industry Data Security Standard (PCI DSS) Flashcards

1
Q

If a company suffers from a breach of customer credit card records, under the terms of PCI DSS, what organization may choose to purse an investigation of this matter?

A
  • bank
  • PCI is enforced through contractual relationships between merchants and their banks
  • law enforcement can be used for criminal investigations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How often does PCI DSS require application vulnerability scans?

A

at least annually and after any change in the application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What technology may be put in place that eliminates the PCI DSS requirement for recurring web vulnerability scans?

A

PCI DSS allows organizations to choose between performing annual web vulnerability assessment tests or installing a web application firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 6 major objectives of PCI/DSS?

A
  1. a secure network must be maintained in which transactions can be conducted
  2. cardholder information must be protected wherever it is stored
  3. systems should be protected against the activities of malicious hackers
  4. cardholder data should be protected physically as well as electronically
  5. networks must be constantly monitored and regularly tested
  6. a formal information security policy must be defined, maintained and followed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly