What encryption does PCI DSS require for wireless networks transmitting cardholder data?
- A.No wireless encryption needed since encryption removes a system component from the cardholder data environment automatically
- B.Any encryption is acceptable, because the standard accepts any cipher suite shipped as a vendor default as strong cryptography
- C.Strong encryption such as WPA2 (AES/CCMP) or WPA3 must be used; WEP and WPA with TKIP are not considered strong cryptography
- D.WEP is acceptable, on the reasoning that the standard permits clear-text account data on internal links between data centres
Why C is correct
PCI DSS requires strong wireless encryption like WPA2-AES or WPA3. WEP and WPA-TKIP have known vulnerabilities and are not acceptable.
Know someone studying for PCI DSS? Send them this one.