Which statement about a visitor log is correct?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Which statement about a visitor log is correct?

Explanation:
Keeping a visitor log is about creating a verifiable record of who enters areas that hold cardholder data, so you can trace access and respond to any incidents. The best statement captures the full scope: it describes maintaining a physical audit trail of visitors to the facility and to computer rooms or data centers where cardholder data is stored or transmitted, including the visitor’s name, the firm represented, and the onsite personnel authorizing access, with retention for at least three months. This supports accountability and security reviews. Other options don’t fit because access logging isn’t optional, limiting the log to just the date omits critical identification and authorization details, and there’s no requirement that logs must be electronic only (hard copies are acceptable as part of a robust physical access record).

Keeping a visitor log is about creating a verifiable record of who enters areas that hold cardholder data, so you can trace access and respond to any incidents. The best statement captures the full scope: it describes maintaining a physical audit trail of visitors to the facility and to computer rooms or data centers where cardholder data is stored or transmitted, including the visitor’s name, the firm represented, and the onsite personnel authorizing access, with retention for at least three months. This supports accountability and security reviews.

Other options don’t fit because access logging isn’t optional, limiting the log to just the date omits critical identification and authorization details, and there’s no requirement that logs must be electronic only (hard copies are acceptable as part of a robust physical access record).

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy