How long should the visitor log be retained, unless law requires otherwise?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

How long should the visitor log be retained, unless law requires otherwise?

Explanation:
The fundamental idea is to set a practical minimum retention window for visitor logs to support security review and incident response. Under PCI DSS, keeping visitor logs for a minimum period of 90 days (about three months) provides enough recent data to trace access to restricted areas and investigate events, while avoiding unnecessary long-term storage. If laws or regulations require a longer period, that would take precedence, but the standard baseline is three months. Retaining for six months or a year goes beyond the minimum and isn’t required by the standard, and keeping logs indefinitely introduces privacy and storage concerns. So the best choice is to retain the visitor log for a minimum of three months, unless law requires otherwise.

The fundamental idea is to set a practical minimum retention window for visitor logs to support security review and incident response. Under PCI DSS, keeping visitor logs for a minimum period of 90 days (about three months) provides enough recent data to trace access to restricted areas and investigate events, while avoiding unnecessary long-term storage. If laws or regulations require a longer period, that would take precedence, but the standard baseline is three months. Retaining for six months or a year goes beyond the minimum and isn’t required by the standard, and keeping logs indefinitely introduces privacy and storage concerns. So the best choice is to retain the visitor log for a minimum of three months, unless law requires otherwise.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy