Question

Difficulty: MediumData Privacy and Compliance Regulations

An IT technician at a service center is auditing workstation configuration requirements for employees who process credit card payments over the phone. The technician needs to ensure that primary account numbers (PAN) are encrypted and that full card verification values (CVV) are never stored on local storage drives after authorization. Which of the following compliance standards specifies these mandatory cardholder data protection requirements?

  1. PCI-DSSAnswer
  2. B
    HIPAA
  3. C
    GDPR
  4. D
    FERPA

Answer

PCI-DSS (Payment Card Industry Data Security Standard) is the compliance framework that mandates strict technical controls for securing credit card numbers and prohibiting the post-authorization storage of sensitive card authentication data.
PCI-DSS applies specifically to organizations handling payment card data. Its operational guidelines dictate technical requirements for protecting Cardholder Data (CHD), requiring encryption for stored account numbers and strictly forbidding the storage of sensitive authentication data such as full CVV codes after transaction authorization.

Step-by-Step Solution

1
Identify the type of sensitive data described in the scenario
The data consists of payment card details, specifically primary account numbers (PAN) and card verification values (CVV).
Determining the data category narrows down which regulatory privacy or security framework applies.
2
Map the data category to the governing compliance standard
Cardholder Data (CHD) handling and storage rules fall strictly under PCI-DSS.
PCI-DSS sets actionable technical guidelines prohibiting post-authorization CVV storage and requiring encryption of stored cardholder details.

Key Concept

Data Privacy and Compliance Regulations (PCI-DSS vs HIPAA/GDPR/FERPA)
Estimated Time:1m 0s
Rate this question