How is skimming used to target PCI data? - answer Copying payment card numbers by
tampering with POS devices, ATMs, Kiosks or copying the magnetic stripe using
handheld skimmers.
How is phishing used to target PCI data? - answer By doing reconnaissance work
through social engineering and or breaking in using software vulnerabilities or e-mails.
How can Payment Data be Monetized? - answerably skimming the card to get the full
track of data, and then making another like card. Using the card information in a "Card-
not-present transactions such as e-commerce or mail order, Telephone order. Card
data is also sold in bulk to other criminals who perform their own fraud using the stolen
data.
Who all are targeted ? - answerRetail, Food and Beverage, Hospitality, Financial
Services, non-profit. EVERYONE!
What is the PCI SSC ? - answerPayment Card Industry Security Service Counsel is an
independent industry standards body providing oversight of the development and
management of Payment Card Industry Data Security Standards on a global basis.
What are some of the PCI SSC founding payment brands. - answerAmerican Express,
Discover Financial, JCB International, Master Card, Visa inc.
What are the Resources provided by the PCI SSC? - answerPCI DSS, PA-DSS, P2PE,
PTS (POI, HSM and PIN) Card Production, and supporting documents.
Roster of QSAs, PA-QSAs, PCIPs, ASVs, validated payment applications, PTS
Devices, and P2PE solutions
PCI Security Standards Counsil FAQs
Education and Outreach programs
Participating Organization Membership, Community Meetings, feedback.
What is the overview of PCI DSS? - answerCovers security of the envrionments that
store, process or transmit account data.
, Environements receive account data from payment applications and other seoucres
(e.g.., acquirers)
what is the overview of PCI PA-DSS - answerCovers secure payment applications to
support PCI DSS compliance
Payment application recieves account data from PIN-entry devices (PEDs) or other
devices and begins payment transaction.
What is the overview of PCI P2PE - answerCovers encryption, decryption, and Key
management requirements for point to point encryption solutions.
What is the overview of PCI PTS-POI? - answerCovers the protection of sensitive data
at the point of interaction devices and their secure components, including cardholder
PINs and account data, and the cryptographic keys used in connection with the
protection of that cardholder data.
What is the overview of PCI PTS-PIN Security? - answerCovers secure management,
processing and transmission of personal identification number (PIN) data during online
and offline payment card transaction processing.
What is the overview of PCI PTS-HSM - answerCovers physical, logical and device
security requirements for securiing hardware security modules.
What is the overview of PCI Card Production - answerCovers physical and logical
security requirements for systems and business processes.
What PCI DSS compliance program does American Express develop and maintain? -
answerData Security Operating Policy (DSOP)
What PCI DSS compliance program does Discover develop and maintain? -
answerDiscover Information Security Compliance (DISC)
What PCI does DSS compliance program does JCB develop and maintain? -
answerData Security Program
What PCI does DSS compliance program dose MasterCard develop and maintain? -
answerSite Data Protection
What PCI does DSS compliance program dose VISA Inc develop and maintain?What
PCI does DSS compliance program dose MasterCard develop and maintain? -
answerCardholder Information Security Program (CISP) Account Information Security
(AIS) program
What is all included in the Payment brand Compliance programs? - answerTracking and
enforcement
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller jw638729. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.99. You're not tied to anything after your purchase.