Posted: November 22nd, 2022

lab #3 case study on pci dss noncompliance: cardsystems solutions

Lab #3 – Assessment Worksheet

Save Time On Research and Writing
Hire a Pro to Write You a 100% Plagiarism-Free Paper.
Get My Paper

Case Study on PCI DSS Noncompliance: CardSystems Solutions

Course Name and Number: _____________________________________________________     Student Name: ________________________________________________________________ 

Instructor Name: ______________________________________________________________

Lab Due Date: ________________________________________________________________ 

Save Time On Research and Writing
Hire a Pro to Write You a 100% Plagiarism-Free Paper.
Get My Paper

Overview

In this lab, you reviewed a real-world case study that involved a PCI DSS noncompliance 

scenario, and you recommended mitigation remedies to prevent the loss of private data for 

similar organizations. 

Lab Assessment Questions & Answers 

1.  Did CardSystems Solutions break any federal or state laws? 

2.  In June 2004, an external auditor certified CardSystems Solutions as Payment Card Industry Data 

Security Standard-(PCI DSS-) compliant. What is your assessment of the auditor’s findings?

3.  Can CardSystems Solutions sue the auditor for not performing his or her tasks and deliverables 

with accuracy? Do you recommend that CardSystems Solutions pursue this avenue?

4.  Who do you think is negligent in this case study and why?

5.  Do the actions of CardSystems Solutions warrant an “unfair trade practice” designation as stated 

by the Federal Trade Commission (FTC)?

26| LAB #3 Case Study on PCI DSS Noncompliance: CardSystems Solutions

6.  What security policies do you recommend to help with monitoring, enforcing, and ensuring PCI 

DSS compliance?

7.  What security controls and security countermeasures do you recommend for CardSystems 

Solutions to be in compliance with PCI DSS requirements?

8.  What was the end result of the attack and security breach to CardSystems Solutions and its 

valuation?

9.  What are the possible consequences associated with the data loss?

10. Who do you think is ultimately responsible for CardSystems Solutions’ lack of PCI DSS 

compliance?

11. What should CardSystems Solutions have done to mitigate possible SQL injections and data 

breaches on its credit card transaction-processing engine?

12. True or false: Although CardSystems Solutions had proper security controls and security 

countermeasures, it was not 100 percent PCI DSS-compliant because the company failed to 

properly implement ongoing monitoring and testing on its development and production systems.

Expert paper writers are just a few clicks away

Place an order in 3 easy steps. Takes less than 5 mins.

Calculate the price of your order

You will get a personal manager and a discount.
We'll send you the first draft for approval by at
Total price:
$0.00
error: Content is protected !!
Open chat
1
Order through WhatsApp!
professionalsessays.com
Hello!
You Can Now Place your Order through WhatsApp
 

 

Order your essay today and save 30% with the discount code 2022DISCOUNT