QuestionQ166

Privacy Operational Lifecycle: Protect

Which of the following are required access-control measures under the Payment Card Industry Data Security Standard (PCI DSS), EXCEPT?

  • A Restrict physical access to cardholder data.
  • B Update antivirus software before granting access.
  • C Assign a unique ID to each person with computer access.
  • D Restrict access to cardholder data by business need-to-know.
Explanation

PCI DSS access-control measures include limiting cardholder-data access according to business need-to-know, uniquely identifying users, and restricting physical access to cardholder data. Maintaining antivirus software supports protection against malicious software, rather than serving as a required access-control condition before access is granted.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!