CAS-002 · Question #590
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in…
The correct answer is B. Industry standard. PCI DSS is an industry standard created by the major payment card brands, not a government regulation or internal company policy.
Question
A medium-sized company has recently launched an online product catalog. It has decided to keep the credit card purchasing in-house as a secondary potential income stream has been identified in relation to sales leads. The company has decided to undertake a PCI assessment in order to determine the amount of effort required to meet the business objectives Which compliance category would this task be part of?
Options
- AGovernment regulation
- BIndustry standard
- CCompany guideline
- DCompany policy
How the community answered
(34 responses)- A3% (1)
- B88% (30)
- C6% (2)
- D3% (1)
Why each option
PCI DSS is an industry standard created by the major payment card brands, not a government regulation or internal company policy.
Government regulations are laws enacted by legislative bodies such as HIPAA, GDPR, or SOX - PCI DSS is not enacted by any government and carries no statutory legal force.
The Payment Card Industry Data Security Standard (PCI DSS) is established and maintained by the PCI Security Standards Council, a body formed by Visa, Mastercard, American Express, Discover, and JCB. It is an externally mandated industry standard that organizations must comply with to accept card payments, placing it firmly in the industry standard compliance category.
A company guideline is an internal, optional recommendation created within an organization - PCI DSS is an external, mandatory standard imposed by the payment card industry.
A company policy is a binding internal rule set by an organization for its own employees and operations - PCI DSS originates from an external industry council, not the company itself.
Concept tested: PCI DSS classification as an industry compliance standard
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.