1. A cloud provider that processes third-party credit card payments is unable to encrypt its customers' cardholder data because of constraints on a legacy payment processing system. What should it implement to maintain Payment Card Industry Data Security Standard (PCI DSS) compliance?

Answer: A

Explanation:

Implementing a compensating control is necessary to maintain PCI DSS compliance.

To address the inability to encrypt cardholder data due to legacy system constraints, implementing a compensating control is essential for maintaining compliance with Payment Card Industry Data Security Standard (PCI DSS).

A) Compensating control

Compensating controls are alternative security measures used when the standard security requirements cannot be met due to technical constraints. In this scenario, the legacy payment processing system's limitations prevent the encryption of credit card data, making a compensating control necessary to mitigate risk and maintain PCI DSS compliance.

B) Risk acceptance

Risk acceptance is the decision to accept the risk associated with a vulnerability without implementing any controls. This option is not suitable in this context since the provider must take steps to protect cardholder data rather than simply accepting the risk of non-compliance with PCI DSS requirements.

C) Protection levels

Protection levels refer to various tiers of security measures that can be implemented. However, this option does not specifically address the need for a compensating control when encryption cannot be employed, making it an inadequate response to the situation described.

D) Privacy control

Privacy controls focus on the management of personal information and do not directly address the specific requirements of PCI DSS related to the protection of cardholder data. This option fails to provide a solution for compliance in the context of encryption constraints.

Conclusion

Implementing a compensating control is the best response to the inability to encrypt credit card data due to legacy system limitations, as it allows the cloud provider to meet PCI DSS compliance requirements. Other options, such as risk acceptance, protection levels, and privacy controls, do not adequately address the need for security measures in this scenario. Therefore, A is the only valid choice to ensure compliance and protect sensitive customer information.