ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an operational risk assessment for a U.S.-hosted e-commerce platform that will store shoppers' payment-card data, you discover the project plan omits any tasks related to complying with the Payment Card Industry Data Security Standard (PCI DSS). From a regulatory or contractual standpoint, which adverse outcome is the project most likely to encounter if it goes live without first achieving PCI DSS compliance?
Civil fines under the CAN-SPAM Act for sending marketing emails without an opt-out link on order-confirmation messages.
A consent decree from the Federal Trade Commission (FTC) requiring independent audits of online advertising practices.
Monetary penalties from card brands and potential suspension of the organization's card-processing privileges for PCI DSS violations.
Export-control sanctions for failing to obtain an International Traffic in Arms Regulations (ITAR) license for the site's cryptographic libraries.
Because the platform will store and process cardholder data, it is automatically in scope for PCI DSS. If the merchant launches the service without demonstrating compliance, the card brands and acquiring bank can impose significant monthly non-compliance fines and may suspend or terminate the merchant's ability to process payment cards until the deficiencies are remediated. By contrast, issues such as additional privacy-notice updates, marketing-practice audits, or software export-control reviews are governed by other legal frameworks and are not direct, immediate consequences of PCI DSS non-compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS and why is it important for businesses that handle payment-card data?
Open an interactive chat with Bash
What are the consequences for a business failing to comply with PCI DSS?
Open an interactive chat with Bash
What steps must a business take to achieve PCI DSS compliance for an e-commerce platform?
Open an interactive chat with Bash
What is PCI DSS, and why is it important?
Open an interactive chat with Bash
What happens if an organization fails to comply with PCI DSS?
Open an interactive chat with Bash
Who enforces PCI DSS compliance, and how is it monitored?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)