PCI-DSS(Payment Card Industry Data Security Standards)와 관련된 신용 카드 데이터를 분류할 때 다음 중 기본 보안 요구 사항은 무엇입니까?
정답: C
The primary security requirement for classifying credit card data related to Payment Card Industry Data Security Standards (PCI-DSS) is encryption of data. PCI-DSS is a set of standards and guidelines that define the security requirements and best practices for protecting the credit card data of the customers and the merchants. PCI-DSS applies to any organization that stores, processes, or transmits credit card data, such as banks, retailers, or service providers. Encryption of data is the primary security requirement for classifying credit card data related to PCI-DSS, as it can protect the confidentiality, integrity, and availability of the credit card data, and prevent unauthorized access, disclosure, modification, or loss of the credit card data. Encryption of data means using cryptographic algorithms and keys to transform the credit card data into an unreadable or unintelligible format, that can only be reversed or decrypted by authorized parties.
Encryption of data can be applied to the credit card data at rest, such as when it is stored in a database, file, or device, or to the credit card data in transit, such as when it is transmitted over a network, channel, or protocol. Processor agreements with card holders, three-year retention of data, and specific card disposal methodology are not primary security requirements for classifying credit card data related to PCI-DSS. These are some of the secondary or supplementary security requirements or practices that may be implemented to enhance the security of the credit card data, but they are not as essential or critical as encryption of data. Processor agreements with card holders are contracts or agreements that define the terms and conditions of the credit card processing services, such as the fees, charges, liabilities, or disputes, between the credit card processors and the card holders. Three-year retention of data is a policy or regulation that specifies the maximum period of time that the credit card data can be retained or stored by the organization, before it must be deleted or destroyed. Specific card disposal methodology is a procedure or technique that describes how to properly dispose or destroy the credit card data or the credit card itself, such as by shredding, wiping, or burning, to prevent any recovery or reuse of the credit card data.