CompTIA Project+ (PK0-005)Basics of IT and GovernanceHard
A global e-commerce company is implementing a new payment processing system. Due to the sensitive nature of financial transactions, the project manager must ensure that the system adheres to strict industry security standards and regulatory requirements across different geographical regions. Which type of compliance framework is MOST relevant for this project?
- APCI DSS
- BGDPR
- CHIPAA
- DISO 9001
Show answer & explanationAnswer & explanation
Correct answer: A. PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that process, store, or transmit credit card information maintain a secure environment. This is directly relevant for a payment processing system.
Why the other options are wrong
- B. GDPR (General Data Protection Regulation) protects personal data of EU citizens, which might apply in conjunction, but PCI DSS is specific to payment card data security.
- C. HIPAA (Health Insurance Portability and Accountability Act) is a US law protecting patient health information, not financial transactions.
- D. ISO 9001 is a standard for quality management systems, not specific to payment security.
PCI DSS
Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
- Mandatory for all entities handling credit card data.
- Aims to reduce credit card fraud.
- Includes requirements for network security, data protection, vulnerability management, and access control.
Memory trick: Regulations Rule Risky Records.