Question

Difficulty: EasyRegulatory Compliance and Legal Requirements Management

An online retail business directly processes customer credit card transactions and stores cardholder account information. Which of the following regulatory compliance standards specifically mandates security controls for safeguarding this payment card data?

  1. Payment Card Industry Data Security Standard (PCI-DSS)Answer
  2. B
    Health Insurance Portability and Accountability Act (HIPAA)
  3. C
    Sarbanes-Oxley Act (SOX)
  4. D
    Federal Information Security Modernization Act (FISMA)

Answer

Payment Card Industry Data Security Standard (PCI-DSS)
The Payment Card Industry Data Security Standard (PCI-DSS) is an information security standard designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment.

Step-by-Step Solution

1
Analyze the data type described in the scenario
The system processes and stores customer credit card details and cardholder data.
Determining the regulatory framework depends on identifying the exact type and classification of regulated data.
2
Match the data type to its governing security compliance standard
PCI-DSS directly governs merchant technical and operational requirements for credit card data.
Payment card security mandates are established specifically by the major payment card brands under PCI-DSS.

Key Concept

Regulatory Compliance and Legal Requirements Management
Rate this question