312-50V11 · Question #808
The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to
The correct answer is C. Assign a unique ID to each person with computer access.. PCI DSS Requirement 8 - assigning unique IDs to each user - falls specifically under the 'Implement strong access control measures' objective, enabling accountability and traceability of access.
Question
The Payment Card Industry Data Security Standard (PCI DSS) con ai s six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"?
Options
- ARegularly test security systems and processes.
- BEncrypt transmission of cardholder data across open, public networks.
- CAssign a unique ID to each person with computer access.
- DUse and regularly update anti-virus software on all systems commonly affected by malware.
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C94% (32)
Why each option
PCI DSS Requirement 8 - assigning unique IDs to each user - falls specifically under the 'Implement strong access control measures' objective, enabling accountability and traceability of access.
Regularly testing security systems and processes maps to the PCI DSS objective 'Regularly monitor and test networks,' not access control.
Encrypting cardholder data transmission over public networks falls under the 'Protect cardholder data' objective, specifically Requirement 4.
PCI DSS Requirement 8 (Identify and Authenticate Access to System Components) mandates assigning a unique ID to every user with computer access, which directly supports the 'Implement strong access control measures' objective. Unique IDs ensure that all actions on cardholder data systems can be attributed to a specific individual, enabling accountability and audit trails.
Maintaining and updating anti-virus software is part of the 'Maintain a vulnerability management program' objective, specifically Requirement 5.
Concept tested: PCI DSS access control objectives and requirement mapping
Source: https://www.pcisecuritystandards.org/document_library/
Topics
Community Discussion
No community discussion yet for this question.