Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 5 páginas
Examen

PCIP Study Guide 2017 updated to pass

Document preview thumbnail
Vista previa 2 fuera de 5 páginas

PCIP Study Guide 2017 updated to pass PA-DSS Payment Application Data Security Standard (POS, shopping carts, etc.) PTS (POI) Pin Transaction Security Point of Interaction Standard (Attended and Unattended Devices) HSM (PIN) Hardware Security Module Pin Standard (not required but may assist in becoming compliant) P2PE Point to Point Encryption Standard (Most helpful standard to reduce scope) SRED Secure Read and Exchange Module allows terminals to be approved for secure encryption of cardholder data. POI Examples Attended : Cash Registers Unattended Encrypted PIN Pads : ATM Unattended Payment Terminals : Gas Pump PCI PIN Security Requirements Management Processing Transmission Payment Card Flow Cardholder presents card - Acquirer asks payment brand to determine issuer - Payment brand network determines issuer and requests approval- Issuer approves purchase- Payment brand network sends approval to the acquirer - Acquirer sends approval to merchant- Cardholder completes purchase and receives receipt. Aquirer (Also Called?) -Merchant Bank -Independent Sale Organization (ISO) -Payment Brand (Amex, Discover, JCB) -Never Visa or Mastercard Payment Card Flow (Clearing) Acquirer sends purchase information to the payment brand network - payment brand network sends purchase information to the issuer - issuer prepares data for cardholder statement - payment brand network provides complete reconciliation to acquirer. Payment Card Flow (Settlement) Issuer determines acquirer via the payment brand network - Issuer sends payment to acquirer - Acquirer pays merchant for cardholders purchase - Issuer bills cardholder Service Provider A business that is not a payment brand, directly involved in the processing, storage or transmission of cardholder data on behalf of another entity. Sometimes a service provider is a merchant. QIR's

Vista previa del contenido

PCIP Study Guide 2017 updated to pass
PA-DSS
Payment Application Data Security Standard (POS, shopping carts, etc.)
PTS (POI)
Pin Transaction Security Point of Interaction Standard (Attended and Unattended
Devices)
HSM (PIN)
Hardware Security Module Pin Standard (not required but may assist in becoming
compliant)
P2PE
Point to Point Encryption Standard (Most helpful standard to reduce scope)
SRED
Secure Read and Exchange Module allows terminals to be approved for secure
encryption of cardholder data.
POI Examples
Attended : Cash Registers
Unattended Encrypted PIN Pads : ATM
Unattended Payment Terminals : Gas Pump
PCI PIN Security Requirements
Management
Processing
Transmission
Payment Card Flow
Cardholder presents card -> Acquirer asks payment brand to determine issuer ->
Payment brand network determines issuer and requests approval-> Issuer approves
purchase-> Payment brand network sends approval to the acquirer -> Acquirer sends
approval to merchant-> Cardholder completes purchase and receives receipt.
Aquirer (Also Called?)
-Merchant Bank
-Independent Sale Organization (ISO)
-Payment Brand (Amex, Discover, JCB)
-Never Visa or Mastercard
Payment Card Flow (Clearing)
Acquirer sends purchase information to the payment brand network -> payment brand
network sends purchase information to the issuer -> issuer prepares data for cardholder
statement -> payment brand network provides complete reconciliation to acquirer.
Payment Card Flow (Settlement)
Issuer determines acquirer via the payment brand network -> Issuer sends payment to
acquirer -> Acquirer pays merchant for cardholders purchase -> Issuer bills cardholder
Service Provider
A business that is not a payment brand, directly involved in the processing, storage or
transmission of cardholder data on behalf of another entity. Sometimes a service
provider is a merchant.
QIR's

, Qualified Integrators and Resellers
-Assure quality and provide feedback
What QIR's do?
-Implementing applications into a merchant environment
-Integrating applications into new software or systems.
-Configuring the payment application
-Servicing payment applications to provide troubleshooting/remote updates or support.
PA-DSS Implementation Guide
-What the QIR uses in order to implement a PCI DSS compliant payment application
into a CDE environment.
-After installation the QIR creates an implementation statement and gives it to the
customer for their signature.
CID
Card Identification Number (American Express)
CAV2/CID/CVC2/CW2
Card specific code on back of card (Discover, JCB, Mastercard, Visa)
Cardholder Data
-PAN
-Cardholder Name
-Expiration Date
-Service Code
Sensitive Authentication Data
-Full magnetic stripe data or chip data
-CAV2/CVC2/CVV2/CID
-PINs/PIN blocks
-Cannot be stored after authorization
Track 1 Data
Contains all fields of Both Track 1 and Track 2
-Length up to 79 characters.
Track 2 Data
Provides shorter processing time for older dial up transmissions.
-Length up to 40 characters
Inventorying Cardholder Environment
-System Name
-Cardholder data stored
-Reason for storage
-Retention period
-Protection mechanism.
Is storing track data permitted after authorization?
No
PCI DSS Goals
-Build and maintain a secure network and systems
-Protect Cardholder Data
-Maintain a vulnerability management program
-Implement strong access control measures

Información del documento

Subido en
30 de septiembre de 2023
Número de páginas
5
Escrito en
2023/2024
Tipo
Examen
Contiene
Preguntas y respuestas
$13.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
magdamwikash23
3.9
(14)
Vendido
114
Seguidores
94
Artículos
5328
Última venta
2 meses hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes