Security Metrics Flashcards
1
Q
What does PCI mean?
A
Payment Card Industry
2
Q
What does DSS mean?
A
Data Security Standard
3
Q
SSC
A
Security Standards Council
4
Q
System components that are likely in scope for your environment.
A
- Networking devices
- Servers
- Switches
- Routers
- Computing devices
- Applications
5
Q
CDE
A
Cardholder Data Environment
6
Q
SAQ
A
Self Assessment Questionnaire
7
Q
How many different SAQ Types are there and what is the overriding distinction between them?
A
Nine.
It’s determined by the methods you use to accept, process, store payments and card data.
8
Q
What are some reasons I can use for the increase in PCI fee?
A
PCI DSS 4.0
- Enhanced to meet the security needs of the payments industry
- **as technology progresses we reap benefits but this is one of the drawbacks amongst all the benefits
- Enhance validation measures and procedures
- Authentication info is now required to be encrypted (pre-authorization). Before it was merely recommended
9
Q
PAN
A
Primary Account Number
10
Q
SAQ-A
A
- Card not present only
- Entirely outsourced
- No storage on site
- All handled by PCI DSS compliant 3rd party
- Card payments are via a re-direct to 3rd-party
11
Q
SAQ A-EP
A
- Merchant only accept E-commerce transactions
- All cardholder data, except the payment page, is outsourced to 3rd party
- Your e-commerce website does not receive cardholder data but does direct them to 3rd party
- Your company does not store, process, or transmit cardholder data on your systems or premises
- Any cardholder data your company retains is on paper, and not received electronically
12
Q
SAQ B
A
- company only uses a knucklebuster or standalone dial-out terminals to take payment information
- the standalone, dial-out terminals are not connected to any other systems
- the standalone, dial-out terminals are not connected to the Internet
- CHD is stored on paper, not electronically
13
Q
SAQ B-IP
A
- Standalone IP devices
- Standalone IP devices are not connected to any other systems in your environment
- Standalone IP device does not rely on any other device to connect to payment processor
- Your company does not store cardholder data electronically
- Paper receipts, no electronic receipts
14
Q
SAQ C
A
- Your business has a payment app system and an internet connection on the same device
- The payment application isn’t connected to any other systems in your environment
- Paper only cardholder data storage and not electronic storage
15
Q
SAQ C-VT
A
- Your company only processes payments through a virtual payment terminal accessed by an internet-connected web browser
- Your company’s virtual terminal is hosted by a PCI DSS 3rd-party service provider
- Your computer is not connected to other locations or systems within your environment
- Your computer does not store cardholder data
- There is not attached hardware that captures or stores CHD
- Paper only storage and not received electronically
- Your company does not store cardholder data in electronic format