{"id":4288,"date":"2024-04-27T06:15:11","date_gmt":"2024-04-27T12:15:11","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=regulations&#038;p=4288"},"modified":"2024-06-03T15:23:19","modified_gmt":"2024-06-03T21:23:19","slug":"pci-ssc","status":"publish","type":"regulations","link":"https:\/\/trustarc.com\/regulations\/pci-ssc\/","title":{"rendered":"PCI Security Standards Council (PCI SSC)"},"content":{"rendered":"\t\t<section id=\"block_0dd7dce8f944217386b4924bc01713b3\" class=\"hero-section-colors text-center bg-navy-gradient\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<span class=\"sub-title block font-bold \">Standard<\/span>\n\t\t\t\t\t\t\t\t\t\t<h1>PCI Security Standards Council (PCI SSC)<\/h1>\n\t\t\t\t\t<p>The Payment Card Industry (PCI) Security Standards Council (SSC) is an international organization who collaborates with payment industry professionals and stakeholders to curate payment data security resources and industry best practices. The PCI SSC develops Data Security Standards (PCI DDS), which provides the latest technical requirements needed to design secure data payment applications.<\/p>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_bf891d6933136faca91aae5bc7d5317d\" class=\"columns-one text-left\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Are you subject to PCI SSC?<\/h2>\n<p style=\"text-align: center\">Any entities or merchants who store, process or transmit cardholder data, sensitive authentication data, and\/or payment transactions must comply with relevant PCI Standards. Software developers and manufacturers who develop payment applications and devices are also subjected to relevant standards.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_1617a1a59bd1983adf3ab5146c44f811\" class=\"columns-two\" style=\"padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t\t<div class=\"heading text-center max-width\">\n\t\t\t\t\t\t\t\t\t\t\t<h2>Key obligations of the PCI DSS V4.0<\/h2>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Minimal storage of account data<\/h4>\n<p>Organizations must develop a data retention policy specifying that only minimal cardholder data must be kept (e.g. a holder\u2019s primary account number (PAN) and card expiration date), and identify locations to retain the data to reduce risk of data compromise.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Implementation of audit logs<\/h4>\n<p>Organizations need to implement audit log mechanisms across all system components and cardholder data to promptly detect and alert administrators of suspicious activities or unauthorized changes to accounts. Audit logs should also track changes to administrative privileges to prevent risks associated with an individual disabling the audit log system.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_97598c15a6c81e06a58734354332ba88\" class=\"columns-two\" style=\"padding-top:0;padding-bottom:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Configuration of network security controls<\/h4>\n<p>Organizations must establish an internal configuration policy outlining what is permitted and\/or not permitted within the database and network to manage network traffic between and from cardholder data environments (CDE).<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Do not store sensitive authentication data after authorization<\/h4>\n<p>Sensitive authentication data, such as PINs and card verification codes, must not be retained once an authorized process is completed. If this data needs to be stored before completion, it must be encrypted with strong cryptography using a different key than the one used for encrypting the PAN.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t<section id=\"block_c18cc99ea46a8becbe50c9670a85fb99\" class=\"columns-two\" style=\"padding-top:0;\">\n\t\t<div class=\"container\">\n\t\t\t\t\t\t<div class=\"col-wrap\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<h4>Implementation and testing of security systems<\/h4>\n<p>Organizations must develop and keep up-to-date security policies and technical mechanisms to ensure the entire system network is secure, and regularly test rigor of the security mechanisms to effectively respond to abnormal activities.<\/p>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_006320aa034113e800fbac96527dea98\" class=\"cta-section has-gradient-purple color-white\">\n\t\t\t<div class=\"bg\">\n\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png\" class=\"attachment-full size-full\" alt=\"\" srcset=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue.png 1440w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-300x102.png 300w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-1024x347.png 1024w, https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/bg-cta-plus-full-blue-768x260.png 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/>\t\t\t<\/div>\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"text-block\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"block h6\">Whitepaper<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<h2 class=\"h1\">Privacy and Data Security in Mergers &amp; Acquisitions<\/h2>\n\t\t\t\t\t\t<p>Data can be a valuable asset or an incredible liability to your business. Proactive data privacy practices are strategically critical in this data economy because of the extreme cost of mistakes today.<\/p>\n\t\t\t\t\t\t<ul class=\"btn-list\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"\/resource\/privacy-and-data-security-in-mergers-acquisitions\/\" class=\"btn\"><span>Learn More<\/span><\/a>\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_34347afc6b9a226b7c4f55fe51357eff\" class=\"columns-one text-center\" style=\"padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Consent.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<h2 style=\"text-align: center\">Achieve compliance<\/h2>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_f338ec297bafb0044dd9a9d3cfba2890\" class=\"cards-block\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"cards-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/assessment-manager\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Assessment Manager<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy program development and compliance management<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automatically identify gaps and track compliance with PrivacyCentral for PC DSS v4.0, SOC2, ISO, NIST, and other privacy and security standards.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/data-inventory-mapping\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Data Inventory Hub &amp; Risk Profile<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Complete and maintain a data inventory<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Automate with a Data Inventory Hub to track where payment data is stored and retained. Save time and reduce risk with automated data flow mapping, risk analysis, and remediation for personal data processes and general activities associated.<\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"card-no-img\" href=\"\/products\/privacy-data-governance\/nymity-research\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h6>Nymity Research<\/h6>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Guidance and operational templates<\/h4>\n\t\t\t\t\t\t\t\t\t<p>Stay ahead of framework changes with expert guidance, ensuring your security and program practices remain compliant and up to date. Operationalize quickly with expert written operational templates for sample policies, checklists, training, and more. <\/p>\n\t\t\t\t\t\t\t\t<span class=\"arrow\">\n\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/icon-long-arrow.svg\" alt=\"\" \/>\n\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_53726bcd18a9f400b3b63ae868944d1b\" class=\"accordions-section\" style=\"\">\n\t\t\t<div class=\"container\">\n\t\t\t\t<div class=\"max-width\">\n\t\t\t\t\t\t\t\t\t\t  <h2>FAQs<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t<ul class=\"accordion\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">How do I apply the PCI DSS into my business operations?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>The PCI SSC is not responsible for enforcing compliance; the responsibility falls on payment brands and banks. Payment brands must establish internal policies guiding cardholder and payment security practices, and these practices shall be adopted by acquiring banks who must also develop their own approach that their customers must adhere to in compliance with the PCI Standards.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Do I notify the PCI SSC in the event of a cardholder data incident?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>The PCI SSC does not participate in forensic investigations. However, PCI Forensic Investigators can collaborate with entities to aid in the aftermath of such incidents. PCI Forensic Investigators are qualified by the PCI SSC.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t\t\t\t\t<a href=\"#\" class=\"opener\">Does the PCI DSS apply to bank account data?<\/a>\n\t\t\t\t\t\t\t\t\t<div class=\"slide\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"slide-wrap\">\n\t\t\t\t\t\t\t\t\t\t\t<p>Bank account data (e.g. branch identification numbers, bank account numbers, routing numbers) are not payment card data, and the PCI DSS does not apply to such data. However, if a bank account number is also a PAN or contains a PAN, then the PCI DSS applies. However, in the event the PCI SSC does not apply to a certain account number containing elements of PAN, it is strongly recommended that the account number be protected to avoid unauthorized persons from recovering the full PAN from an account number.<\/p>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_b0b1d2f2505081d4b83fa426382b349d\" class=\"resource-section bg-light-grey\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related Resources<\/h2>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-in-healthcare-ensuring-data-security\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy in Healthcare: Ensuring Data Security<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/webinar-privacy-security-it-the-venn-diagram-of-compliance\/\" class=\"resource-single has-icon Webinars\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-gray-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Webinars and Videos<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Privacy, Security, &#038; IT: The Venn Diagram of Compliance<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/what-gdpr-means-cybersecurity-strategy\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-plus-blue-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>What the GDPR Means for your Cybersecurity Strategy<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t\n\n\t\t<section id=\"block_a4a36748352adb06013fa6161f1fb8ac\" class=\"columns-one text-center bg-light-grey\" style=\"padding-top:0;padding-bottom:0;overflow:hidden;\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t<p style=\"font-size: 80%\"><strong>The information provided does not, and is not intended to, constitute legal advice.<\/strong> Instead, all information, content, and materials presented are for general informational purposes only.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>PCI SSC &#8211; International payment security standard<\/p>\n","protected":false},"template":"","regulation":[97],"topic-regulation":[89,87],"class_list":["post-4288","regulations","type-regulations","status-publish","hentry","regulation-international","topic-regulation-security","topic-regulation-standard"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>PCI SSC - International payment security standard | TrustArc<\/title>\n<meta name=\"description\" content=\"The PCI SSC collaborates with payment industry professionals and stakeholders to curate payment data security resources.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/regulations\/pci-ssc\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/pci-ssc\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/regulations\\\/pci-ssc\\\/\",\"name\":\"PCI SSC - International payment security standard | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"datePublished\":\"2024-04-27T12:15:11+00:00\",\"dateModified\":\"2024-06-03T21:23:19+00:00\",\"description\":\"The PCI SSC collaborates with payment industry professionals and stakeholders to curate payment data security resources.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/regulations\\\/pci-ssc\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"PCI SSC - International payment security standard | TrustArc","description":"The PCI SSC collaborates with payment industry professionals and stakeholders to curate payment data security resources.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/regulations\/pci-ssc\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/regulations\/pci-ssc\/","url":"https:\/\/trustarc.com\/regulations\/pci-ssc\/","name":"PCI SSC - International payment security standard | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"datePublished":"2024-04-27T12:15:11+00:00","dateModified":"2024-06-03T21:23:19+00:00","description":"The PCI SSC collaborates with payment industry professionals and stakeholders to curate payment data security resources.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/regulations\/pci-ssc\/"]}]},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations\/4288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulations"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/regulations"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=4288"}],"wp:term":[{"taxonomy":"regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/regulation?post=4288"},{"taxonomy":"topic-regulation","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-regulation?post=4288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}