Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

PCI DSS 3.0 correctly answered latest 2023

Rating
-
Sold
-
Pages
3
Grade
A+
Uploaded on
29-12-2022
Written in
2022/2023

PCI DSS 3.0 correctly answered latest 2023What is PCI DSS ? Payment Card Industry Data Security Standard For consistent data security measures globally 12 measures in six groups PCI DSS is a minimum set of controls It does not supercede local laws and regulations It is a contractual agreement, not a standard PCI-DSS only applies if PANs are stored, processed or transmitted 1. Build and Maintain a secure network Install and maintain a Firewall configuration. Do not use vendor supplied defaults for passwords, and other security parameters. 2. Protect Card Holder Data Protect stored cardholder data Encrypt transmission of cardholder data across open public networks 3. Maintain a vulnerability program Use and regularly update anti-virus software or programs Develop and maintain secure systems and applications 4. Implement strong Access control measures Restrict access to cardholder data by business need to know Assign a unique ID to each person with computer access Restrict physical access to cardholder data 5. Regularly Monitor and Test networks Track and monitor all access to network resources and cardholder data. Regularly test security systems and processes 6. Maintain an Information Security Policy Maintain a policy that addresses Information Security for all personnel Cardholder data Primary Account Number (PAN) Cardholder name Expiration date Service Code Sensitive Authentication Data Magnetic stripe data or equivalent on a chip CAV2/CVC2/CVV2/CID PINs / PIN Blocks What is PA-DSS ? Payment Application Data Security Standard PA-DSS applies to software sold "off the shelf" by 3rd parties PA-DSS does not apply to applications developed by merchants and service providers for use in-house. (this is covered by PCI-DSS) PCI-DSS applies to All system components (VMs, switches, routers, hypervisors, Firewalls, Wireless Access Points, Servers, Applications, Inc Internet based services, Network Services like NTP, DNS) Scope IS a Primary requirement cardholder data flows help set scope business practices and processes need careful consideration and may need re-engineering. Network Segmentation is Recommended Wireless Use only for non-sensitive data Carefully consider the Risk MUST be tested Service Providers Need their own PCI-DSS compliance or will have their services reviewed as part of their customers audits. The Report on Compliance (ROC) documents the role of each service provider. Sampling Sampling of Business Facilities / System components is allowed, however all applicable PCI DSS requirements must be considered. Compensating Controls a Compensating Controls Worksheet must be completed for each compensating control. And documented in the ROC. Report on Compliance contains 1. Executive Summary Description of the entity's payment card business and the High Level network diagram. 2. Details of Scope of Work and approach taken Validation of the Scope Environment on which the assessment is focussed Segmentation Details of sampling Other related entities that require compliance Wireless Lans Version of requirements used 3. Details about the reviewed environment Cardholder data flows Hardware and Software (Assets) Services Providers Individuals Interviewed Documents reviewed For MSPs, which requirements apply (and which are the responsibility of the customer) 4. Contact Information and report date 5. Quarterly Scan results ASV scan results (for all external IP addresses) 6. Findings and Observations Compliance Completion Steps 1.Complete the ROC 2. Provide evidence of passing scans from ASV 3. Complete the "Attestation of compliance" 4. Submit all to the Aquirer, or Payment Brand PCI SSC Payment card Industry Security Standards Council ASV Approved Scanning Vendors QSA Qualified Security Assessor

Show more Read less
Institution
PCI DSS
Course
PCI DSS








Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
PCI DSS
Course
PCI DSS

Document information

Uploaded on
December 29, 2022
Number of pages
3
Written in
2022/2023
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$8.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Thumbnail
Package deal
Bundle for PCI DSS exam
-
9 2022
$ 104.91 More info

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BravelRadon Havard School
View profile
Follow You need to be logged in order to follow users or courses
Sold
919
Member since
4 year
Number of followers
540
Documents
46343
Last sold
2 days ago
EXAM HUB

Welcome to Exam Hub Are you looking for high-quality, exam-ready notes, past papers, Test Banks, and well-researched study materials to boost your grades? You’re in the right place! I create and upload detailed, easy-to-understand, and well-structured documents across multiple subjects. All my materials are designed to help you study , save time, and excel in your coursework and exams! On this page NURSING EXAMS,STUDY GUIDES,TESTBANKS AND QUALITY EXAMS IS THE KEY TO STUDENTS CAREER EXCELLENCE, you find all documents, package deals, and flashcards offered by BravelRadon (EXAM HUB STORES!)....kindly recommend a friend for A+ GARANTEEd either you are a first-year student or final-year graduation! best of luck!

Read more Read less
3.5

159 reviews

5
57
4
30
3
33
2
8
1
31

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions