100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached
logo-home
PCIP questions and answers graded A+ 2023 $12.99   Add to cart

Exam (elaborations)

PCIP questions and answers graded A+ 2023

 0 view  0 purchase
  • Course
  • Institution

PCIP questions and answers graded A+ 2023 Requirement 1 Install and maintain a firewall configuration to protect cardholder data Requirement 2 Do not use vendor supplied defaults for system passwords and other security parameters Requirement 3 Protect stored cardholder data by enacting a fo...

[Show more]

Preview 2 out of 9  pages

  • September 30, 2023
  • 9
  • 2023/2024
  • Exam (elaborations)
  • Questions & answers
avatar-seller
PCIP questions and answers graded A+ 2023
Requirement 1
Install and maintain a firewall configuration to protect cardholder data
Requirement 2
Do not use vendor supplied defaults for system passwords and other security
parameters
Requirement 3
Protect stored cardholder data by enacting a formal data retention policy and implement
secure deletion methods
Requirement 4
Encrypt transmission of cardholder data across open, public networks
Requirement 5
Protect all systems against malware and regularly update anti-virus software or
programs
Requirement 6
Develop and maintain secure systems and applications
Requirement 7
Restrict access to cardholder data by business need to know
Requirement 8
Identify and authenticate access to system components
Requirement 9
Restrict physical access to cardholder data
Requirement 10
Track and monitor all access to network resources and cardholder data
Requirement 11
Regularly test security systems and processes
Requirement 12
Maintain a policy that addresses information security for all personnel
Appendix A1
Shared hosting providers must protect the cardholder data environment
Appendix A2
Additional PCI DSS Requirements for Entities using SSL/early TLS
Appendix A3
Designated Entities Supplemental Validation (DESV)
Compensating Controls
1- Meet the intent and rigor of the original PCI requirement
2- Sufficiently offset the risk that the original PCI DSS requirement was designed to
defend against
3- Be "above and beyond" other PCI DSS requirements (i.e., not simply in compliance
with other requirements)
4- Be commensurate with additional risk imposed by not adhering to original
requirement
Compensating Controls -
To consider Compensating Controls, one of the following must exist that precludes
implementing the stated control:

, 1- Legitimate Technical Constraint
2- Documented Business Constraint
Compensating Controls :
Existing PCI DSS requirements CANNOT be considered as compensating controls if
they are already required for the
Compensating Controls ...
Existing PCI DSS requirements may be combined with new controls to become a
compensating control
SAQs
is a validation tool intended to assist merchants and service providers in self-evaluating
their compliance with the PCI DSS
SAQ A
Card-Not-Present (e-commerce or MO/TO) merchants, all cardholder data functions
outsourced to PCI DSS compliant service providers.
Not applicable to face-to-face channels.
SAQ A-EP
E-commerce merchants who outsource all payment processing to PCI DSS validated
third parties, and who have a website(s) that doesn't directly receive cardholder data but
that can impact the security of the payment transaction. No electronic storage,
processing, or transmission of any cardholder data on the merchant's systems or
premises.
Applicable only to
e-commerce channels.
SAQ B
Imprint-only merchants with no electronic cardholder data storage, or standalone, dial-
out terminal merchants with no electronic cardholder data storage.
Not applicable to e-commerce channels.
SAQ B-IP
Merchants using only stand-alone, PTS-approved payment terminals with an IP
connection to the payment processor, with no electronic cardholder data storage.
Not applicable to e-commerce channels.
SAQ C
Merchants with segmented payment application systems connected to the Internet, with
no electronic cardholder data storage.
Not applicable to e-commerce channels.
SAQ C-VT
Merchants using only web-based virtual payment terminals, with no electronic
cardholder data storage.
Not applicable to e-commerce channels.
SAQ D
SAQ D for Merchants: All merchants not included in the descriptions for other SAQ
types.
SAQ D for Service Providers: All service providers identified by a payment brands as
eligible to complete a self-assessment questionnaire.
P2PE

The benefits of buying summaries with Stuvia:

Guaranteed quality through customer reviews

Guaranteed quality through customer reviews

Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.

Quick and easy check-out

Quick and easy check-out

You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.

Focus on what matters

Focus on what matters

Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!

Frequently asked questions

What do I get when I buy this document?

You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.

Satisfaction guarantee: how does it work?

Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.

Who am I buying these notes from?

Stuvia is a marketplace, so you are not buying this document from us, but from seller magdamwikash23. Stuvia facilitates payment to the seller.

Will I be stuck with a subscription?

No, you only buy these notes for $12.99. You're not tied to anything after your purchase.

Can Stuvia be trusted?

4.6 stars on Google & Trustpilot (+1000 reviews)

78252 documents were sold in the last 30 days

Founded in 2010, the go-to place to buy study notes for 14 years now

Start selling
$12.99
  • (0)
  Add to cart