312-50V13 · Question #390
Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?
The correct answer is C. PCI-DSS. For a penetration tester and auditor at a credit card company, the Payment Card Industry Data Security Standard (PCI-DSS) is the most relevant information security standard as it governs the protection of cardholder data.
Question
Options
- AFISMA
- BHITECH
- CPCI-DSS
- DSarbanes-OxleyAct
How the community answered
(18 responses)- B6% (1)
- C89% (16)
- D6% (1)
Why each option
For a penetration tester and auditor at a credit card company, the Payment Card Industry Data Security Standard (PCI-DSS) is the most relevant information security standard as it governs the protection of cardholder data.
FISMA (Federal Information Security Modernization Act) is a US law that requires federal agencies to develop, document, and implement information security programs.
HITECH (Health Information Technology for Economic and Clinical Health Act) is a US law that promotes the adoption and meaningful use of health information technology, primarily dealing with patient health information.
PCI-DSS (Payment Card Industry Data Security Standard) is a set of security standards designed to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. A penetration tester for a credit card company would specifically audit compliance with these regulations.
The Sarbanes-Oxley Act (SOX) is a US federal law that mandates certain practices in financial record keeping and reporting for public companies, focusing on financial integrity, not specifically credit card data security.
Concept tested: Compliance standards (PCI-DSS)
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.