問題文
A national retailer is designing a new architecture that will store cardholder account numbers so that its fraud team can review disputed purchases. The retailer is privately held, trades in one country only, and that country has no sector privacy statute covering retail. Which body of requirements most directly constrains how the architect protects those stored account numbers?
選択肢
- The design is constrained first by the listed company filing statute published for that data.
- The design is constrained first by the payment card industry standard published for that data.
- The design is constrained first by the workplace safety notice rule published for that data.
- The design is constrained first by the medical record privacy rule published for that data.