Which PCI DSS requirement restricts physical access to cardholder data?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Which PCI DSS requirement restricts physical access to cardholder data?

Explanation:
Controlling physical access to cardholder data is about making sure that only authorized people can reach the hardware, storage media, and facilities where cardholder data is stored or processed. This is the explicit physical-security control in PCI DSS, covering things like securing data centers and server rooms, managing access lists, using visitor logs, and properly handling or disposing of media containing CHD. It’s the right choice because it directly targets the physical barriers and procedures that prevent someone from tampering with or stealing data by physically reaching the devices. The other items focus on different areas: monitoring and logging who accesses network resources and CHD, protecting data as it moves across networks (encryption in transit), and having a broad information-security policy for all personnel. While all are important, they don’t specifically address restricting physical access to cardholder data.

Controlling physical access to cardholder data is about making sure that only authorized people can reach the hardware, storage media, and facilities where cardholder data is stored or processed. This is the explicit physical-security control in PCI DSS, covering things like securing data centers and server rooms, managing access lists, using visitor logs, and properly handling or disposing of media containing CHD. It’s the right choice because it directly targets the physical barriers and procedures that prevent someone from tampering with or stealing data by physically reaching the devices.

The other items focus on different areas: monitoring and logging who accesses network resources and CHD, protecting data as it moves across networks (encryption in transit), and having a broad information-security policy for all personnel. While all are important, they don’t specifically address restricting physical access to cardholder data.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy