Answers
PCI DSS - answer Payment Card Industry Data Security Standard
For consistent data security measures globally
12 requirements in six groups
PCI DSS is a minimum set of controls
It is a contractual agreement, not a standard
PCI-DSS only applies if PANs are stored, processed or transmitted
PCI Goal 1 - answer Build and Maintain a secure network
PCI Goal 2 - answer Protect Card Holder Data
PCI Goal 3 - answer Maintain a vulnerability program
PCI Goal 4 - answer Implement strong Access control measures
PCI Goal 5 - answer Regularly Monitor and Test networks
PCI Goal 6 - answer Maintain an Information Security Policy
Cardholder data - answer Primary Account Number (PAN)
Cardholder name
Expiration date
Service Code
Sensitive Authentication Data - answer Magnetic stripe data or equivalent on a chip
CAV2/CVC2/CVV2/CID
PINs / PIN Blocks
PA-DSS - answer Payment Application Data Security Standard
PA-DSS applies to software sold "off the shelf" by 3rd parties
PA-DSS does not apply to applications developed by merchants and service providers
for use in-house. (this is covered by PCI-DSS)
Scope - answer Is a primary requirement
cardholder data flows help set scope
business practices and processes need careful consideration and may need re-
engineering.
, Network Segmentation is - answer Recommended to reduce scope and risk
When can Wireless be used? - answer Use only for non-sensitive data
Carefully consider the Risk
MUST be tested
Service Providers - answer Need their own PCI-DSS compliance or will have their
services reviewed as part of their customers audits.
The Report on Compliance (ROC) documents the role of each service provider.
Sampling - answer Sampling of Business Facilities / System components is allowed,
however all applicable PCI DSS requirements must be considered.
Compensating Controls - answer a Compensating Controls Worksheet must be
completed for each compensating control. And documented in the ROC.
Compliance Completion Steps - answer 1.Complete the ROC
2. Provide evidence of passing scans from ASV
3. Complete the "Attestation of compliance"
4. Submit all to the Aquirer, or Payment Brand
PCI SSC - answer Payment card Industry Security Standards Council
ASV - answer Approved Scanning Vendors
QSA - answer Qualified Security Assessor
PCI PA-DSS - answer Payment card Industry Payment Application Data Security
Standard
PCI PED - answer Payment Card Industry Pin Entry Devices
Merchant levels - answer Defined by payment brands.
Levels 1 to 4
1 is the largets merchants or merchants who have been compromised. 6 Million
transactions/year +
Non-compliance consequences - answer Fines according to Level and elapsed time
determined by payment brands
Breach Consequences - answer Fine per cardholder data compromised / Loss of
reputation / customer trust / suspension of service by credit card account provider
Firewall and Router rule sets be reviewed at least every - answer 6 Months