ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 477 - CAS-004 discussion

Report
Export

A compliance officer is responsible for selecting the right governance framework to protect individuals' data. Which of the following is the appropriate framework for the company to consult when collecting international user data for the purpose of processing credit cards?

A.
ISO 27001
Answers
A.
ISO 27001
B.
COPPA
Answers
B.
COPPA
C.
NIST 800-53
Answers
C.
NIST 800-53
D.
PCI DSS
Answers
D.
PCI DSS
Suggested answer: D

Explanation:

PCI DSS (Payment Card Industry Data Security Standard) is the most appropriate governance framework when collecting and processing credit card data, including international user data. PCI DSS establishes security standards for organizations that handle payment card transactions and ensures the protection of cardholder data globally. The other options, such as ISO 27001 and NIST 800-53, provide general security frameworks, but PCI DSS is specifically designed for payment card security, which is critical when handling credit card information. CASP+ emphasizes the role of PCI DSS in ensuring the secure handling of payment data.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (PCI DSS Compliance for Payment Systems)

CompTIA CASP+ Study Guide: Payment Systems Security and PCI DSS

asked 02/10/2024
josny Cameus
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first