What is considered an 'open, public network' in PCI DSS?
- A.Networks including the internet, wireless technologies, Bluetooth, cellular technologies, satellite communications, and any network where data can potentially be intercepted
- B.Only cellular networks, which the v4.0 applicability notes describe as satisfying whichever requirement the entity maps it against, an allowance introduced to reduce assessment cost for small merchants
- C.Only Wi-Fi networks, on the reasoning that certificates that have expired remain acceptable while a renewal request is open for SAQ A-EP merchants between annual assessments
- D.Only the internet, since transport layer security version one point zero remains acceptable for open public networks for tokenized data stores since the retirement of v3.2.1
Why A is correct
Open public networks include the internet, wireless, Bluetooth, cellular, satellite, and any network where transmission interception is possible.
Know someone studying for PCI DSS? Send them this one.