nerdexam
CompTIA

CAS-002 · Question #590

A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in…

The correct answer is B. Industry standard. PCI DSS is an industry standard created by the major payment card brands, not a government regulation or internal company policy.

Integration of Computing, Communications and Business Disciplines

Question

A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in relation to sales leads. The company has decided to undertake a PCI assessment in order to determine the amount of effort required to meet the business objectives Which compliance category would this task be part of?

Options

  • AGovernment regulation
  • BIndustry standard
  • CCompany guideline
  • DCompany policy

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    88% (30)
  • C
    6% (2)
  • D
    3% (1)

Why each option

PCI DSS is an industry standard created by the major payment card brands, not a government regulation or internal company policy.

AGovernment regulation

Government regulations are laws enacted by legislative bodies such as HIPAA, GDPR, or SOX - PCI DSS is not enacted by any government and carries no statutory legal force.

BIndustry standardCorrect

The Payment Card Industry Data Security Standard (PCI DSS) is established and maintained by the PCI Security Standards Council, a body formed by Visa, Mastercard, American Express, Discover, and JCB. It is an externally mandated industry standard that organizations must comply with to accept card payments, placing it firmly in the industry standard compliance category.

CCompany guideline

A company guideline is an internal, optional recommendation created within an organization - PCI DSS is an external, mandatory standard imposed by the payment card industry.

DCompany policy

A company policy is a binding internal rule set by an organization for its own employees and operations - PCI DSS originates from an external industry council, not the company itself.

Concept tested: PCI DSS classification as an industry compliance standard

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#PCI DSS#compliance#industry standards#credit card security

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice