1
PCIP Exam Complete S
1 1 1
tudy Guide with 100%
1 1 1
Correct Questions and1 1 1
Verified Answers | Certi
1 1 1
fied Information
1
Privacy Professional 1
Preparation
,PCI1Data1Security1Standard1(PCI1DSS)1
The1PCI1DSS1applies1to1all1entities1that1store,1process,1and/or1transmit1cardholder1data.1It1c
overs1technical1and1operational1system1components1included1in1or1connected1to1cardholder1
data.1If1you1accept1or1process1payment1cards,1PCI1DSS1applies1to1you.1
Sensitive1Authen1tication1Data1
Merchants,1servic1e1providers,1and1other1
entities1involved1with1payment1card1processing1must1never1store1sensitive1authentication1da1
ta1after1authorization.1T1his1includes1the13-1or14-
1digit1security1code1printed1on1the1front1or1back1of1a1card1(CVD),1the1data1stored1on1a1card's1m
agnetic1stripe1or1chip1(also1called1"Full11Track1Data")11-
1and1personal1identification1numbers1(PIN)1entered1by1the1cardholder.1
1
1
1
1
Card1Verification1Data1Codes1(CVD)1
31or141digit1code1that1further1authenticates1a1not-present1cardholder1Visa-CVV21
MC-1CVC21
Discover-1CVD1
JCB1-CAV21
AmEx1-1CID1
Requirement1111
Install11and1maintain1a1firewall1configuration1to1protect1cardholder1data1
1
1
1
1
Network1devices1in1scope1for1Requirement111
Firewalls1and1Ro1uters-
1Routers1connect1traffic1between1networks,1Firew1alls1control1the1traffic1between1netwo
rks1and1within1internal1network1
QIR1Qualified1Integrators1&1Resellers1
,
, Qualified1Integrators1&1Resellers-
1authorized1by1the1SSC1to1implement,1configure1and/or1support1PA-
DSS1payment1applications.1Visa1requires1all1level141merchants1use1QIRs1for1POS1applicat
ion1and1terminal1installation1and1servicing1
Compensating1Controls1
An1alternative1control,1put1in1place1to1satisfy1the1requirement1for1a1security1measure1th
at1is1deemed1too1difficult1or1impractical1to1implement1at1the1present1time.1
Permitted1reasons1for1using1Compensating1Controls1
Organizations1needing1an1alternative1to1security1requirements1that1could1not1be1met1due1
to1legitimate1technological1OR1documented1business1constraints,1but1has
1sufficiently1mitigated1the1risk1associated1with1the1requirement1through1impl
ementation1of1other1compensating1controls1
Examples1of1Compensating1Controls1
(i)1Segregation1of1Duties1(SOD)1and1(ii)1Encryption1Compensating1
Controls1must:1
1) Meet1the1intent1and1rigor1of1the1original1stated1requirement;1
2) Provide1a1similar1level1of1defense1as1the1original1stated1requirement;1
3) Be1"above1and1beyond"1other1PCI1DSS1requirements1(not1simply1in1compliance1with1
other1PCI1DSS1requirements);1and1
4) Be1commensurate1with1the1additional1risk1imposed1by1not1adhering1to1the1original1st
ated1requirement.1
Compensating1Controls1Worksheet1
1)1Constraint;12)1Objective;13)1Identified1Risk;14)1Define1Compensating1Control;1
5)1Validate1Controls;16)1Maintenance1(COIDVM)1
Card1Data1that1cannot1be1stored1by1Merchants,1Service1providers1after1authorization1Sen
sitive1Authentication1Data.1i)13-1or14-
1digit1security1code1printed1on1the1front1or1back1of1a1card,1ii)1data1stored1on1a1card's1magn
etic1stripe1or1chip1(also1called1"Full1Track1Data"),1and1iii)1personal1identification1numbers1(
PIN)1entered1by1the1cardholder1
Card1Data1that1MAY1be1stored1
i)1cardholder1name,1ii)1service1code1(identifies1industry1iii)1Personal1Account1Number1(
PAN)1iv)1expiration1date1may1be1stored.1
Network1Segmentation1
The1process1of1isolating1the1cardholder1data1environment1from1the1remainder1of1an1entity's1
network1
Not1a1requirement1but1strongly1recommended.1
Report1on1Compliance1(ROC)1
Prepared1at1the1time1of1the1assessment1of1PCI1compliance1and1comprehensively1provides1
details1about1the1assessment1approach1and1compliance1standing1against1each1PCI1DSS1re
quirement1
What1is1included1in1the1Report1on1Compliance1(ROC)?1