CCSP · Question #412
Which of the following is NOT a regulatory system from the United States federal government?
The correct answer is A. PCI DSS. PCI DSS (Payment Card Industry Data Security Standard) is not a government regulation - it is an industry standard created and governed by the PCI Security Standards Council, a private body founded by major credit card brands (Visa, Mastercard, American Express, Discover, JCB)…
Question
Which of the following is NOT a regulatory system from the United States federal government?
Options
- APCI DSS
- BFISMA
- CSOX
- DHIPAA
How the community answered
(30 responses)- A90% (27)
- B3% (1)
- C7% (2)
Explanation
PCI DSS (Payment Card Industry Data Security Standard) is not a government regulation - it is an industry standard created and governed by the PCI Security Standards Council, a private body founded by major credit card brands (Visa, Mastercard, American Express, Discover, JCB). The other three are US federal laws: FISMA (Federal Information Security Management Act) mandates security standards for federal agencies; SOX (Sarbanes-Oxley Act) regulates financial reporting and corporate governance for publicly traded companies; HIPAA (Health Insurance Portability and Accountability Act) protects the privacy and security of patient health information. Compliance with PCI DSS is contractually required, not legally mandated by government.
Topics
Community Discussion
No community discussion yet for this question.