A retail business operating in the European Union accepts online credit card payments from local customers. The security team must update company policies to maintain compliance when handling customer payment card details and personal billing addresses. Which of the following compliance frameworks directly govern the security and privacy of these data types? (Select TWO.)
- Payment Card Industry Data Security Standard (PCI-DSS) for protecting payment cardholder dataCevap
- BHealth Insurance Portability and Accountability Act (HIPAA) for protecting medical health records
- General Data Protection Regulation (GDPR) for safeguarding personal data of individuals in the EUCevap
- DSarbanes-Oxley Act (SOX) for auditing corporate financial accounting statements
Cevap
The Payment Card Industry Data Security Standard (PCI-DSS) and the General Data Protection Regulation (GDPR) are the two compliance frameworks that directly apply to credit card processing and EU customer personal billing data.
The Payment Card Industry Data Security Standard (PCI-DSS) sets security controls for handling credit card numbers and payment data. The General Data Protection Regulation (GDPR) enforces privacy and data protection rights for personal data collected from individuals in the European Union.
Adım Adım Çözüm
Anahtar Kavram
Identifying regulatory scope based on data classification (Cardholder Data vs. PII) to apply appropriate compliance frameworks such as PCI-DSS and GDPR.
Tahmini Süre:45s