An IS auditor is performing an integrated audit covering payment processing activities using point-of-sale (POS) systems. Which of the following findings related to personal identification numbers (PINs) should be of GREATEST concern?
A.
Cardholder PINs are encrypted and stored on the local POS terminal.
B.
Cardholders are not required to enter their PINs.
C.
Cardholders may select any 4-digit PIN without restrictions.
D.
Cardholder PINs are not encrypted on the central computer.
The finding of greatest concern would be option D: Cardholder PINs are not encrypted on the central computer.
While all the options present potential security risks, the lack of encryption on the central computer is the most serious. This is because the central computer is likely to store the PINs of many cardholders, making it a high-value target for attackers. If an attacker were to gain access to the central computer, they could potentially obtain the PINs of all cardholders, leading to a massive data breach.
In contrast, the other options, while still concerning, present less severe risks. For example, option A could lead to a data breach if an individual POS terminal is compromised, but the impact would likely be less severe than a breach of the central computer
Storing encrypted PINs locally on the POS terminal can pose a significant security risk, as it increases the likelihood of unauthorized access and potential compromise of PINs. Best practices involve avoiding the local storage of encrypted PINs, especially in a manner that could be vulnerable to exploitation.
The storage of encrypted PINs on the local POS terminal is generally considered a higher risk due to the potential for direct compromise at the point of entry.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
3008
1 month agoFAGFUR
1 month, 4 weeks ago