nerdexam
(ISC)2

CCSP · Question #412

Which of the following is NOT a regulatory system from the United States federal government?

The correct answer is A. PCI DSS. PCI DSS (Payment Card Industry Data Security Standard) is not a government regulation - it is an industry standard created and governed by the PCI Security Standards Council, a private body founded by major credit card brands (Visa, Mastercard, American Express, Discover, JCB)…

Submitted by renata2k· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following is NOT a regulatory system from the United States federal government?

Options

  • APCI DSS
  • BFISMA
  • CSOX
  • DHIPAA

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    3% (1)
  • C
    7% (2)

Explanation

PCI DSS (Payment Card Industry Data Security Standard) is not a government regulation - it is an industry standard created and governed by the PCI Security Standards Council, a private body founded by major credit card brands (Visa, Mastercard, American Express, Discover, JCB). The other three are US federal laws: FISMA (Federal Information Security Management Act) mandates security standards for federal agencies; SOX (Sarbanes-Oxley Act) regulates financial reporting and corporate governance for publicly traded companies; HIPAA (Health Insurance Portability and Accountability Act) protects the privacy and security of patient health information. Compliance with PCI DSS is contractually required, not legally mandated by government.

Topics

#Regulatory compliance#U.S. federal regulations#Industry standards#PCI DSS

Community Discussion

No community discussion yet for this question.

Full CCSP Practice