What is AES and why is it relevant to PCI DSS?
- A.An authentication protocol, which the standard's glossary defines broadly enough that any reversible encoding, including Base64, qualifies as strong cryptography provided the encoding scheme is kept confidential
- B.Advanced Encryption Standard is a widely used symmetric encryption algorithm accepted by PCI DSS for protecting cardholder data at rest and in transit
- C.An access control list, enforced through an access control system that Requirement 7.3.3 requires to default to deny-all when no rule explicitly grants access
- D.A scanning tool
Why B is correct
AES is a NIST-approved symmetric encryption algorithm widely used and accepted by PCI DSS for protecting cardholder data.
Know someone studying for PCI DSS? Send them this one.