Which security standard governs protection of payment card data?

Prepare for the Certified Ethical Hacker Version 11 Exam. Study with comprehensive questions and explanations. Equip yourself with the skills needed for success!

Multiple Choice

Which security standard governs protection of payment card data?

Explanation:
The standard that governs protection of payment card data is PCI-DSS. This standard, developed by the major card brands through the Payment Card Industry Security Standards Council, applies to any organization that stores, processes, or transmits cardholder data. It covers the life cycle of card data, requiring secure networks, protection of stored data, strong access controls, regular vulnerability management, monitoring and testing of security systems, and maintaining an information security policy. In practice, PCI-DSS enforces practices like encrypting card data in transit, keeping systems patched, restricting who can access card data, and regularly testing security measures. The other standards address different domains—HIPAA for health information, SOX for financial reporting controls, and GLBA for consumer financial privacy in financial institutions—so they aren’t specifically about cardholder data protection like PCI-DSS.

The standard that governs protection of payment card data is PCI-DSS. This standard, developed by the major card brands through the Payment Card Industry Security Standards Council, applies to any organization that stores, processes, or transmits cardholder data. It covers the life cycle of card data, requiring secure networks, protection of stored data, strong access controls, regular vulnerability management, monitoring and testing of security systems, and maintaining an information security policy. In practice, PCI-DSS enforces practices like encrypting card data in transit, keeping systems patched, restricting who can access card data, and regularly testing security measures. The other standards address different domains—HIPAA for health information, SOX for financial reporting controls, and GLBA for consumer financial privacy in financial institutions—so they aren’t specifically about cardholder data protection like PCI-DSS.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy