312-50V10 · Question #808
The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to
The correct answer is C. Assign a unique ID to each person with computer access.. PCI DSS organizes requirements under six control objectives; assigning unique IDs to users falls under 'Implement Strong Access Control Measures' as Requirement 8.
Question
The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?
Options
- ARegularly test security systems and processes.
- BEncrypt transmission of cardholder data across open, public networks.
- CAssign a unique ID to each person with computer access.
- DUse and regularly update anti-virus software on all systems commonly affected by malware.
How the community answered
(18 responses)- A6% (1)
- C94% (17)
Why each option
PCI DSS organizes requirements under six control objectives; assigning unique IDs to users falls under 'Implement Strong Access Control Measures' as Requirement 8.
Regularly testing security systems and processes corresponds to PCI DSS Requirement 11, which falls under the 'Regularly Monitor and Test Networks' objective, not access control.
Encrypting cardholder data transmission over public networks is PCI DSS Requirement 4, which falls under the 'Protect Cardholder Data' objective.
Assigning a unique ID to each person with computer access maps directly to PCI DSS Requirement 8 (Identify and Authenticate Access to System Components), which is explicitly listed under the 'Implement Strong Access Control Measures' objective. Unique user identification ensures individual accountability and prevents shared credentials from obscuring audit trails. This is a foundational access control mechanism that cannot be substituted by the other listed controls for this specific objective.
Using and regularly updating anti-virus software is PCI DSS Requirement 5, which falls under the 'Maintain a Vulnerability Management Program' objective.
Concept tested: PCI DSS control objectives and requirement mapping
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.