What does the policy require regarding storage and maintenance of all media?

Prepare for the PCI DSS Requirements Test with our interactive quizzes. Use multiple choice questions, flashcards, and detailed explanations. Ace your exam with confidence!

Multiple Choice

What does the policy require regarding storage and maintenance of all media?

Explanation:
Managing media that may contain cardholder data requires ongoing visibility into what exists and where it is. The policy should require periodic inventories of all media so you can confirm what media is in the environment, its location, and who has access. Regular inventories enable secure storage, proper lifecycle tracking, and timely destruction of retired media. Daily inventories would be impractical, and having no inventories would leave media unaccounted for. Annual destruction alone doesn’t provide the necessary ongoing oversight. Periodic inventories strike the right balance to maintain control.

Managing media that may contain cardholder data requires ongoing visibility into what exists and where it is. The policy should require periodic inventories of all media so you can confirm what media is in the environment, its location, and who has access. Regular inventories enable secure storage, proper lifecycle tracking, and timely destruction of retired media. Daily inventories would be impractical, and having no inventories would leave media unaccounted for. Annual destruction alone doesn’t provide the necessary ongoing oversight. Periodic inventories strike the right balance to maintain control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy