Soru

Zorluk: ZorData Privacy and Compliance Regulations

An IT technician is performing a security audit on a workstation in a retail company's call center. The technician discovers that customer support agents manually transcribe customer credit card details—including the 16-digit Primary Account Number (PAN), expiration date, and 3-digit Card Verification Value (CVV)—into local text notes for troubleshooting recurring payment errors. Which compliance framework or standard specifically prohibits the storage of sensitive authentication data such as CVV codes after transaction authorization under any circumstance?

  1. Payment Card Industry Data Security Standard (PCI-DSS)Cevap
  2. B
    General Data Protection Regulation (GDPR)
  3. C
    Health Insurance Portability and Accountability Act (HIPAA)
  4. D
    Family Educational Rights and Privacy Act (FERPA)

Cevap

Payment Card Industry Data Security Standard (PCI-DSS)
The Payment Card Industry Data Security Standard (PCI-DSS) establishes strict security requirements for any organization that handles credit or debit card transactions. Under PCI-DSS Requirement 3, storing Sensitive Authentication Data (SAD)—which includes card validation codes (CVV/CVC), full magnetic stripe data, and PINs—after transaction authorization is strictly prohibited under all circumstances, even if encrypted.

Adım Adım Çözüm

1
Analyze the data type involved in the scenario
The workstation contains credit card details, specifically Primary Account Numbers (PAN) and 3-digit Card Verification Values (CVV).
CVV codes fall under the classification of Sensitive Authentication Data (SAD) used in payment processing.
2
Evaluate the regulatory constraints on storing sensitive authentication data
Identify that PCI-DSS Requirement 3 prohibits storing SAD post-authorization regardless of encryption or business justification.
Retaining CVV data creates severe fraud risk if compromised; payment processors and merchants are strictly forbidden from keeping this data once authorization completes.

Anahtar Kavram

PCI-DSS Data Retention and Sensitive Authentication Data Prohibitions
Bu soruyu puanla