PCI ISA
AAA - ANS-Acronym for "authentication, authorization, and accounting." Protocol for
authenticating a person based on their verifiable identity, authorizing a person based on their
person rights, and accounting for a consumer's intake of network assets
Access Control - ANS-Mechanisms that restriction availability of facts or statistics-processing
sources handiest to legal individuals or applications
Account Data - ANS-consists of cardholder statistics and/or touchy authentication statistics
Acquirer - ANS-Also known as "service provider bank," "obtaining financial institution," or
"obtaining monetary institution". Entity, usually a economic organization, that tactics charge card
transactions for traders and is defined by a fee brand as an acquirer. Acquirers are situation to
charge logo regulations and methods concerning merchant compliance
Administrative Access - ANS-Elevated or accelerated privileges granted to an account in order
for that account ot manipulate structures, networks and/or packages.
Adware - ANS-Type of malicious software program that, whilst hooked up, forces a pc to
mechanically display or download advertisements
AES - ANS-Abbreviation for "Advanced Encryption Standard." Block cipher used in symmetric
cryptography followed by way of NIST in November 2001
ANSI - ANS-Acronym for "American National Standards Institute" Private, non-earnings
business enterprise that administers and coordinates the USA voluntary standardization and
conformity assessment machine
Anti-Virus - ANS-Program or software program able to detecting, putting off, and shielding in
opposition to various types of malicious software which include viruses, worms, Trojans
AOC - ANS-Acronym for "attestation of compliance". The AOC is a shape for merchants and
provider vendors to attest to the results of a PCI DSS assessment, as documented in the
Self-Assessment Questionnaire or Report on Compliance
AOV - ANS-Acronym for "attestation of validation". The AOV is a form for PA_QSAs to attest to
the outcomes of a PA_DSS assessment, as documented in the PA-DSS Report on Validation.
Application - ANS-Includes all purchased and custom software program applications or
corporations of programs, which includes both inner and external applications.
, ASV - ANS-Acronym for "authorized Scanning Vendor". Company authorised by the PCI SSC to
conduct outside vulnerability scanning offerings.
Audit Log - ANS-Also referred to as audit trail. Chronological record of device activities.
Provides an independently verifiable trail enough to permit reconstruction, assessment, and
examination of series of environments and sports surrounding or leading to operation, method,
or occasion in a transaction from inception to very last consequences.
Authentication - ANS-Process of verifying identification of an man or woman, device, or process.
Authentication Credentials - ANS-Combination of the consumer ID or account ID plus the
authentication elements used to authenticate and individual, tool, or technique
Authorization - ANS-In the context of get entry to controls, authorization is the granting of get
entry to or other rights to a user, software, or manner.
In the context of a a payment card transaction, authorization happens whilst a merchant
receives transaction approval after the acquirer to validates the transaction with the
company/processor.
Backup - ANS-A reproduction of facts that is made in case the authentic information is
misplaced or broken. The backup can be used to repair the authentic statistics.
BAU - ANS-An acronym for "commercial enterprise as typical".
Bluetoot - ANS-_____ is a wireless protocol designed for transmitting information over brief
distances, changing cables.
Buffer Overflow - ANS-This attack takes place when an attacker leverages a vulnerability in an
utility, causing records to be written to a memory place (that is, a buffer) it is being utilized by a
exclusive application.
Card Skimmer - ANS-A bodily device, regularly attached to legitimate card-analyzing tool,
designed to illegitimately capture and/or keep the facts from a price card.
Compensating Controls - ANS-can be considered whilst an entity can not meet a demand
explicitly as stated, due to valid technical or documented business constraints, but has
sufficiently mitigated the threat associated with the requirement thru implementation of different
controls.
Cross-Site Scripting (XSS) - ANS-Vulnerability this is created from insecure coding techniques,
resulting in mistaken input validation.
AAA - ANS-Acronym for "authentication, authorization, and accounting." Protocol for
authenticating a person based on their verifiable identity, authorizing a person based on their
person rights, and accounting for a consumer's intake of network assets
Access Control - ANS-Mechanisms that restriction availability of facts or statistics-processing
sources handiest to legal individuals or applications
Account Data - ANS-consists of cardholder statistics and/or touchy authentication statistics
Acquirer - ANS-Also known as "service provider bank," "obtaining financial institution," or
"obtaining monetary institution". Entity, usually a economic organization, that tactics charge card
transactions for traders and is defined by a fee brand as an acquirer. Acquirers are situation to
charge logo regulations and methods concerning merchant compliance
Administrative Access - ANS-Elevated or accelerated privileges granted to an account in order
for that account ot manipulate structures, networks and/or packages.
Adware - ANS-Type of malicious software program that, whilst hooked up, forces a pc to
mechanically display or download advertisements
AES - ANS-Abbreviation for "Advanced Encryption Standard." Block cipher used in symmetric
cryptography followed by way of NIST in November 2001
ANSI - ANS-Acronym for "American National Standards Institute" Private, non-earnings
business enterprise that administers and coordinates the USA voluntary standardization and
conformity assessment machine
Anti-Virus - ANS-Program or software program able to detecting, putting off, and shielding in
opposition to various types of malicious software which include viruses, worms, Trojans
AOC - ANS-Acronym for "attestation of compliance". The AOC is a shape for merchants and
provider vendors to attest to the results of a PCI DSS assessment, as documented in the
Self-Assessment Questionnaire or Report on Compliance
AOV - ANS-Acronym for "attestation of validation". The AOV is a form for PA_QSAs to attest to
the outcomes of a PA_DSS assessment, as documented in the PA-DSS Report on Validation.
Application - ANS-Includes all purchased and custom software program applications or
corporations of programs, which includes both inner and external applications.
, ASV - ANS-Acronym for "authorized Scanning Vendor". Company authorised by the PCI SSC to
conduct outside vulnerability scanning offerings.
Audit Log - ANS-Also referred to as audit trail. Chronological record of device activities.
Provides an independently verifiable trail enough to permit reconstruction, assessment, and
examination of series of environments and sports surrounding or leading to operation, method,
or occasion in a transaction from inception to very last consequences.
Authentication - ANS-Process of verifying identification of an man or woman, device, or process.
Authentication Credentials - ANS-Combination of the consumer ID or account ID plus the
authentication elements used to authenticate and individual, tool, or technique
Authorization - ANS-In the context of get entry to controls, authorization is the granting of get
entry to or other rights to a user, software, or manner.
In the context of a a payment card transaction, authorization happens whilst a merchant
receives transaction approval after the acquirer to validates the transaction with the
company/processor.
Backup - ANS-A reproduction of facts that is made in case the authentic information is
misplaced or broken. The backup can be used to repair the authentic statistics.
BAU - ANS-An acronym for "commercial enterprise as typical".
Bluetoot - ANS-_____ is a wireless protocol designed for transmitting information over brief
distances, changing cables.
Buffer Overflow - ANS-This attack takes place when an attacker leverages a vulnerability in an
utility, causing records to be written to a memory place (that is, a buffer) it is being utilized by a
exclusive application.
Card Skimmer - ANS-A bodily device, regularly attached to legitimate card-analyzing tool,
designed to illegitimately capture and/or keep the facts from a price card.
Compensating Controls - ANS-can be considered whilst an entity can not meet a demand
explicitly as stated, due to valid technical or documented business constraints, but has
sufficiently mitigated the threat associated with the requirement thru implementation of different
controls.
Cross-Site Scripting (XSS) - ANS-Vulnerability this is created from insecure coding techniques,
resulting in mistaken input validation.