1 / 3100%
1
Cyber Security
Student`s Name
Institutional Affiliation
Course
Instructor`s Name
Date
2
Cyber Security
The Payment Card Industry (PCI) is a standard that major card providers initially
developed to address all public issues concerning their respective credit cards (Razikin &
Widodo, 2021). The key credit card companies came together to form the Security Standards
Council (SSC), and the result was the formation of the Data Security Standard (DSS). The most
significant security policies outlined by the PCI are the security standards for both processing
and holding data within the credit card. Unlike the PCI DSS, which plays a significant role in
providing privacy to the industry's self-regulation, the Federal Information Security Management
Act (FISMA), on the other hand, ensures the government has regulation over its information
security (Xie, 2019). The key security policies outlined by FISMA include risk analysis and
system security certification based on all standards developed by the NIST. Finally, the Control
Objective for Information and Related Technology (COBIT) includes providing a library of
security controls that play a significant role in ensuring corporate compliance with the Sarbanes-
Oakley Act (SOX) (Bouayad et al., 2021). Other security standards outlined by COBIT include
ensuring the private sector follows the regulations and policy lifecycle management.
The security policies outlined by the PCI DSS can be used in any entity that plays a
significant role in producing, processing, or storing credit card data. Nevertheless, two key
industries where such policies can be applied include the Health Insurance Portability and
Accounting Act (HIPAA). They help in transmitting and storing Protected Healthcare
Information (PHI). Another industry is the Government Agencies, where FISMA helps palsy a
key role towards ensuring both standards and organizations within that industry comply with a
variety of standards at once.
3
References
Bouayad, H., Benabbou, L., & Berrado, A. (2021). Aligning Information Technology and Supply
Chain: An Approach to Map SCOR to COBIT. International Journal of Information
System Modeling and Design (IJISMD), 12(3), 1-26.
Razikin, K., & Widodo, A. (2021). General Cybersecurity Maturity Assessment Model: Best
Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS)
Compliance. CommIT (Communication and Information Technology) Journal, 15(2), 91-
104.
Xie, S. L. (2019). A must for agencies or a candidate for deletion: A grounded theory
investigation of the relationships between records management and information security.
Records Management Journal.
Students also viewed