When developing security processes for handling credit card data on the business unit's information system, the information security manager should FIRST:
A.
ensure that systems that handle credit card data are segmented.
B.
review industry best practices for handling secure payments.
C.
ensure alignment with industry encryption standards.
D.
review corporate policies regarding credit card information.
(PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.
Unlike other security standards, you can have your own company policy (lower than industry standard) as baseline, PCI-DSS is the baseline
B. is preferred
The information security manager FIRST review corporate policies regarding credit card information. This step is crucial as it sets the foundation for security processes within the organization. By understanding and adhering to the corporate policies, the information security manager can ensure that the handling of credit card data aligns with the organization's guidelines and compliance requirements. This step provides a framework for implementing appropriate security measures and helps address any potential gaps or issues in the existing policies. Once this foundation is established, the information security manager can then proceed to the other options mentioned, such as ensuring systems are segmented, reviewing industry best practices, and ensuring alignment with encryption standards.
D. Review corporate policies regarding credit card information.
This is the first step because it's essential to understand the organization's existing policies and compliance requirements related to credit card data handling. Once you have a clear understanding of the internal policies, you can then proceed to align with industry encryption standards (option C), review industry best practices (option B), and ensure that systems are segmented (option A). However, the foundation for secure credit card data handling is established by adhering to your organization's policies and compliance mandate
B. review industry best practices for handling secure payments.
upvoted 4 times
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
bdabef2
1 week, 4 days agoAlexJacobson
8 months, 2 weeks agoxcjxcj
7 months, 2 weeks agokoala_lay
1 year agoCert_IT
1 year, 1 month agooluchecpoint
1 year, 1 month agoBl1024
1 year, 1 month agodevilend
1 year, 3 months agorichck102
1 year, 3 months agoshiowbah
1 year, 7 months ago