CAS-001 · Question #347
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in…
The correct answer is B. Industry standard. PCI DSS (Payment Card Industry Data Security Standard) is an industry standard, not a government regulation. It was created and is maintained by the PCI Security Standards Council - a private body founded by major card brands (Visa, Mastercard, American Express, Discover, and…
Question
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in relation to sales leads. The company has decided to undertake a PCI assessment in order to determine the amount of effort required to meet the business objectives. Which compliance category would this task be part of?
Options
- AGovernment regulation
- BIndustry standard
- CCompany guideline
- DCompany policy
How the community answered
(32 responses)- B94% (30)
- C3% (1)
- D3% (1)
Explanation
PCI DSS (Payment Card Industry Data Security Standard) is an industry standard, not a government regulation. It was created and is maintained by the PCI Security Standards Council - a private body founded by major card brands (Visa, Mastercard, American Express, Discover, and JCB) - and applies to any organization that stores, processes, or transmits cardholder data. It is not enacted by any government legislature (ruling out 'Government regulation'), and it is not something the company created internally (ruling out 'Company guideline' and 'Company policy'). Compliance is contractually required by payment card agreements, placing it firmly in the category of an industry standard.
Topics
Community Discussion
No community discussion yet for this question.