CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A retail company that processes credit card payments must implement security controls required by the Payment Card Industry Data Security Standard (PCI DSS), which is enforced through merchant agreements rather than government law. This is best classified as which type of compliance requirement?
- ARegulatory compliance
- BContractual/industry compliance
- CCommon law compliance
- DStatutory compliance
Show answer & explanationAnswer & explanation
Correct answer: B. Contractual/industry compliance
PCI DSS is not government legislation but a set of requirements imposed by the payment card industry through contracts merchants sign with card brands and processors, making it a contractual/industry compliance obligation.
Why the other options are wrong
- A. Regulatory compliance stems from government agencies enforcing law, unlike PCI DSS.
- C. Common law compliance relates to court precedent, not industry standards.
- D. Statutory compliance refers to laws passed by legislative bodies.
Contractual vs Regulatory Compliance
Contractual compliance obligations arise from agreements between private parties (e.g., PCI DSS), while regulatory/statutory compliance arises from government law.
- PCI DSS = industry/contractual standard
- GDPR/HIPAA = regulatory/statutory law
- Both carry penalties but differ in enforcement source
Memory trick: Contracts Come from Companies, Regulations Come from Government