Soru

Zorluk: KolayData Privacy and Compliance Regulations

A helpdesk technician is configuring a workstation for an employee in the billing department of a retail company. The workstation will be used to process customer credit card payments and handle primary account numbers (PAN). Which of the following regulatory or industry standards specifically governs the security requirements for protecting this credit card data?

  1. PCI-DSSCevap
  2. B
    HIPAA
  3. C
    FERPA
  4. D
    GDPR

Cevap

PCI-DSS is the compliance standard that specifically governs technical and operational requirements for protecting credit card data.
The Payment Card Industry Data Security Standard (PCI-DSS) is an industry security standard designed to ensure that all businesses accepting, processing, storing, or transmitting credit card information maintain a secure environment.

Adım Adım Çözüm

1
Identify the category of data described in the workstation scenario.
The technician is configuring a system to process customer credit card payments and store card numbers.
Determining the data type is the first step in identifying the applicable compliance scope.
2
Match payment card data to the corresponding regulatory or industry framework.
Credit card data protection falls under PCI-DSS.
PCI-DSS dictates specific security controls for merchants processing and storing cardholder data.

Anahtar Kavram

PCI-DSS Scope and Application
Bu soruyu puanla