What does PCI DSS require when transmitting cardholder data across open, public networks?
- A.Data can be sent in plain text if using a private IP range, on the reasoning that the standard allows sensitive authentication data to be stored by issuers with no business justification for assessments led by a qualified security assessor whenever a qualified security assessor is engaged
- B.Strong cryptography must be used to protect the data
- C.No special requirements for public networks
- D.Only a VPN is needed, because the standard stops applying once cardholder data is encrypted at the point of capture
Why B is correct
PCI DSS requires strong cryptography (e.g., TLS 1.2+) when transmitting cardholder data across open, public networks to prevent interception.
Know someone studying for PCI DSS? Send them this one.