350-201 Question 17
Single answerA financial services company is implementing strict compliance measures to protect customer payment data and ensure regulatory adherence. Which compliance standard is MOST relevant to this scenario?
- A
PCI DSS
- B
FISMA
- C
FedRAMP
- D
GDPR
Show answer and explanation
Correct answer: A
Explanation
The PCI DSS compliance standard is created to ensure the protection of payment card information and is mandatory for organizations involved in processing, storing, or transmitting credit card data. In this scenario, the financial services company is dealing with customer payment data, making PCI DSS the most relevant compliance standard.
- A. Correct.
PCI DSS (Payment Card Industry Data Security Standard) is specifically designed for organizations handling payment card information to secure cardholder data, making it the most relevant standard for this financial services scenario.
- B. Incorrect.
FISMA (Federal Information Security Management Act) applies to federal agencies and contractors, not directly to financial services involving payment data.
- C. Incorrect.
FedRAMP (Federal Risk and Authorization Management Program) is a compliance standard for cloud services used by federal agencies and is not specific to payment card data.
- D. Incorrect.
GDPR (General Data Protection Regulation) focuses on data privacy and protection for EU citizens but does not specifically address payment card data security.