Question 6

Requirement 3.5 requires document and implement procedures to protect keys used to secure stored cardholder data against disclose and misuse. This requirement applies to keys used to encrypt stored cardholder data, and also applies to key-encrypting keys used to protect data-encrypting keys. Such key-encrypting keys must be
  • Question 7

    Imprint-Only Merchants with no electronic storage of cardholder data may be eligible to use which SAQ?
  • Question 8

    If an e-commerce service provider was deemed eligible to complete an SAQ, which SAQ would they use?
  • Question 9

    PCIPs are required to adhere to the Code of Professional Responsibility, which includes:
  • Question 10

    The lockout of an user ID should be set until an administrator re-enables the user or to a minimum of