An IT technician at a service center is auditing workstation configuration requirements for employees who process credit card payments over the phone. The technician needs to ensure that primary account numbers (PAN) are encrypted and that full card verification values (CVV) are never stored on local storage drives after authorization. Which of the following compliance standards specifies these mandatory cardholder data protection requirements?
- PCI-DSSCevap
- BHIPAA
- CGDPR
- DFERPA
Cevap
PCI-DSS (Payment Card Industry Data Security Standard) is the compliance framework that mandates strict technical controls for securing credit card numbers and prohibiting the post-authorization storage of sensitive card authentication data.
PCI-DSS applies specifically to organizations handling payment card data. Its operational guidelines dictate technical requirements for protecting Cardholder Data (CHD), requiring encryption for stored account numbers and strictly forbidding the storage of sensitive authentication data such as full CVV codes after transaction authorization.
Adım Adım Çözüm
Anahtar Kavram
Data Privacy and Compliance Regulations (PCI-DSS vs HIPAA/GDPR/FERPA)
Tahmini Süre:1m 0s