100-160 Question 252
Single answerA company that processes credit card transactions has been informed of a potential security breach involving customer payment data. Which compliance framework mandates that the company must investigate the breach, report it to the appropriate entities, and potentially notify affected customers within a specific time frame?
- A
GDPR
- B
HIPAA
- C
PCI-DSS
- D
FERPA
Show answer and explanation
Correct answer: C
Explanation
PCI-DSS is the compliance framework that specifically governs the handling of payment card data. In the event of a security breach involving cardholder information, PCI-DSS mandates that organizations must conduct an investigation, report the breach to relevant parties (such as card brands or acquiring banks), and notify affected customers if required. This ensures the integrity and security of payment card systems.
- A. Incorrect.
GDPR is a compliance framework focused on protecting personal data and privacy of individuals within the European Union. While it does mandate breach notification, it is not specific to payment card data.
- B. Incorrect.
HIPAA is designed to protect the privacy and security of healthcare data, primarily for health information. It does not apply to payment card data.
- C. Correct.
PCI-DSS (Payment Card Industry Data Security Standard) is specifically designed to ensure the security of payment card data. It mandates that organizations investigate security breaches involving cardholder data, report incidents to card brands or acquiring banks, and potentially notify affected customers.
- D. Incorrect.
FERPA (Family Educational Rights and Privacy Act) is focused on protecting the privacy of student education records and does not apply to payment card data or breach notifications related to it.