Secure Credit Card Handling

Is the following statement True or False:
It's ok to store credit card information on a post-it note, as long as you throw it away after.

Where possible, avoid writing or documenting credit card information in a physical format. These documents can be easily viewed or stolen and the information on it abused. If writing the information down is unavoidable, ensure the document is securely disposed of (e.g. shredded) when no longer needed. Avoid simply throwing it in the bin.
View Options Again

Understanding the Risks

Protecting Credit Cards

Compliance Obligations

What is the Cardholder Data Environment (CDE)?

What is PCI-DSS and what is its goal?

The Payment Card Industry Data Security Standards (PCI-DSS) are a security framework for organizations handling credit card information. Its primary goal is to prevent data breaches and reduce credit card fraud.
View Options Again

What's a potential impact of PCI-DSS non-compliance?

Non-compliance with PCI-DSS can have significant consequences for businesses, including financial penalties from credit card providers, increased transaction fees by banks, and potential loss of the ability to process credit card payments. Additionally, banks may terminate their relationship with non-compliant businesses due to the risk they pose.
View Options Again

Employee Roles & Responsibilities

Is the following statement True or False:
A Data Custodian is responsible for handling cardholder data on a day-to-day basis.

Data Custodians handle and maintain cardholder data on a day-to-day basis. They must follow strict data handling procedures such as ensuring encryption is used where possible, limiting access to authorized personnel only, using secure storage, and following secure disposal practices.
View Options Again

Data Custodian Best Practices

Is the following statement True or False:
It's ok for a Data Custodian to store credit card information on a personal computer or USB.

Credit card information should never leave the cardholder data environment (CDE) as defined by the business. Storing credit cards on personal devices can be considered a potential data breach and unnecessarily exposes customer information to potentially less secure processes or technologies.
View Options Again

Wrapping up