PCCET · Question #151
Which regulation is specifically mandated to payment account data security?
The correct answer is B. PCI DSS. The Payment Card Industry Data Security Standard (PCI DSS) is the regulation specifically mandated to ensure the security of payment account data.
Question
Which regulation is specifically mandated to payment account data security?
Options
- AGLBA
- BPCI DSS
- CEU GDPR
- DSOX
How the community answered
(32 responses)- A3% (1)
- B94% (30)
- C3% (1)
Why each option
The Payment Card Industry Data Security Standard (PCI DSS) is the regulation specifically mandated to ensure the security of payment account data.
GLBA (Gramm-Leach-Bliley Act) primarily focuses on financial institutions' obligation to explain their information-sharing practices to customers and to safeguard sensitive data.
PCI DSS is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment. Compliance with PCI DSS is mandatory for entities handling cardholder data to protect against payment card fraud.
EU GDPR (General Data Protection Regulation) is a broad data privacy and security law concerning the personal data of EU citizens, not specifically payment account data security as its primary mandate.
SOX (Sarbanes-Oxley Act) addresses corporate governance and financial reporting accuracy, aiming to prevent corporate accounting scandals, rather than directly mandating payment account data security.
Concept tested: Data security compliance regulations
Source: https://www.pcisecuritystandards.org/documents/PCI_DSS_v4-0.pdf
Topics
Community Discussion
No community discussion yet for this question.