CISSP · Question #1335
While classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS), which of the following is a PRIMARY security requirement?
The correct answer is C. Encryption of data. PCI-DSS mandates encryption as a core requirement to protect cardholder data, making it the primary security control when classifying credit card data.
Question
While classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS), which of the following is a PRIMARY security requirement?
Options
- AProcessor agreements with card holders
- BThree-year retention of data
- CEncryption of data
- DSpecific card disposal methodology
How the community answered
(40 responses)- A3% (1)
- C95% (38)
- D3% (1)
Why each option
PCI-DSS mandates encryption as a core requirement to protect cardholder data, making it the primary security control when classifying credit card data.
Processor agreements with cardholders are a contractual or business relationship concern, not a primary PCI-DSS technical security requirement for protecting cardholder data.
PCI-DSS does not mandate a three-year data retention period; in fact, it encourages minimizing data retention and prohibits storing sensitive authentication data after authorization.
PCI-DSS Requirement 3 explicitly mandates the protection of stored cardholder data through strong cryptography, and Requirement 4 requires encryption of cardholder data transmitted across open or public networks. Encryption is a foundational control ensuring that even if data is compromised, it remains unreadable and unusable to unauthorized parties, making it the primary security requirement for PCI-DSS compliance.
While PCI-DSS does address secure disposal of media containing cardholder data (Requirement 9), specific card disposal methodology is a physical security sub-requirement, not the primary security requirement when classifying credit card data.
Concept tested: PCI-DSS primary security requirements for cardholder data
Source: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf
Topics
Community Discussion
No community discussion yet for this question.