Categories: Homework on time

Golden Gate University PCI DSS Noncompliance CardSystems Solutions Lab Did CardSystems Solutions break any federal or state laws? In June 2004, an extern

Golden Gate University PCI DSS Noncompliance CardSystems Solutions Lab Did CardSystems Solutions break any federal or state laws?

In June 2004, an external auditor certified CardSystems Solutions as Payment Card Industry Data
Security Standard- (PCI DSS-) compliant. What is your assessment of the auditor’s findings?

Don't use plagiarized sources. Get Your Custom Essay on
Golden Gate University PCI DSS Noncompliance CardSystems Solutions Lab Did CardSystems Solutions break any federal or state laws? In June 2004, an extern
Just from $13/Page
Order Essay

Can CardSystems Solutions sue the auditor for not performing his or her tasks and deliverables
with accuracy? Do you recommend that CardSystems Solutions pursue this avenue?

Who do you think is negligent in this case study and why?

Do the actions of CardSystems Solutions warrant an “unfair trade practice” designation as stated
by the Federal Trade Commission (FTC) What security policies do you recommend to help with monitoring, enforcing, and ensuring PCI
DSS compliance?What security controls and security countermeasures do you recommend for CardSystems
Solutions to be in compliance with PCI DSS requirements?What was the end result of the attack and security breach to CardSystems Solutions and its
valuation?What are the possible consequences associated with the data loss?Who do you think is ultimately responsible for CardSystems Solutions’ lack of PCI DSS
compliance?What should CardSystems Solutions have done to mitigate possible SQL injections and data
breaches on its credit card transaction-processing engine?True or false: Although CardSystems Solutions had proper security controls and security
countermeasures, it was not 100 percent PCI DSS-compliant because the company failed to
properly implement ongoing monitoring and testing on its development and production systems. 25
Lab #3 – Assessment Worksheet
Case Study on PCI DSS Noncompliance: CardSystems Solutions
Course Name and Number: _____________________________________________________
Student Name: ________________________________________________________________
Instructor Name: ______________________________________________________________
Lab Due Date: ________________________________________________________________
Overview
In this lab, you reviewed a real-world case study that involved a PCI DSS noncompliance
scenario, and you recommended mitigation remedies to prevent the loss of private data for
similar organizations.
Lab Assessment Questions & Answers
1. Did CardSystems Solutions break any federal or state laws?
2. In June 2004, an external auditor certified CardSystems Solutions as Payment Card Industry Data
Security Standard- (PCI DSS-) compliant. What is your assessment of the auditor’s findings?
3. Can CardSystems Solutions sue the auditor for not performing his or her tasks and deliverables
with accuracy? Do you recommend that CardSystems Solutions pursue this avenue?
4. Who do you think is negligent in this case study and why?
5. Do the actions of CardSystems Solutions warrant an “unfair trade practice” designation as stated
by the Federal Trade Commission (FTC)?
Copyright © 2014 by Jones & Bartlett Learning, LLC, an Ascend Learning Company. All rights reserved.
www.jblearning.com
Student Lab Manual
26 | LAB #3 Case Study on PCI DSS Noncompliance: CardSystems Solutions
6. What security policies do you recommend to help with monitoring, enforcing, and ensuring PCI
DSS compliance?
7. What security controls and security countermeasures do you recommend for CardSystems
Solutions to be in compliance with PCI DSS requirements?
8. What was the end result of the attack and security breach to CardSystems Solutions and its
valuation?
9. What are the possible consequences associated with the data loss?
10. Who do you think is ultimately responsible for CardSystems Solutions’ lack of PCI DSS
compliance?
11. What should CardSystems Solutions have done to mitigate possible SQL injections and data
breaches on its credit card transaction-processing engine?
12. True or false: Although CardSystems Solutions had proper security controls and security
countermeasures, it was not 100 percent PCI DSS-compliant because the company failed to
properly implement ongoing monitoring and testing on its development and production systems.

Purchase answer to see full
attachment

superadmin

Share
Published by
superadmin

Recent Posts

Consider the following information, and answer the question below. China and England are internation

Consider the following information, and answer the question below. China and England are international trade…

4 years ago

The CPA is involved in many aspects of accounting and business. Let’s discuss some other tasks, othe

The CPA is involved in many aspects of accounting and business. Let's discuss some other…

4 years ago

For your initial post, share your earliest memory of a laser. Compare and contrast your first percep

For your initial post, share your earliest memory of a laser. Compare and contrast your…

4 years ago

2. The Ajax Co. just decided to save $1,500 a month for the next five years as a safety net for rece

2. The Ajax Co. just decided to save $1,500 a month for the next five…

4 years ago

How to make an insertion sort to sort an array of c strings using the following algorithm: * beg, *

How to make an insertion sort to sort an array of c strings using the…

4 years ago

Assume the following Keynesian income-expenditure two-sector model:

Assume the following Keynesian income-expenditure two-sector model:                                                AD = Cp + Ip                                                Cp = Co…

4 years ago