What is the minimum retention period for audit trails and the requirement that some be available online?

Prepare for the PCI DSS Requirements Test with our interactive quizzes. Use multiple choice questions, flashcards, and detailed explanations. Ace your exam with confidence!

Multiple Choice

What is the minimum retention period for audit trails and the requirement that some be available online?

Explanation:
Auditing and monitoring require a balance between keeping enough history for investigations and having recent activity ready for quick review. PCI DSS mandates that audit trail history be retained for at least one year, with a minimum of three months of that history available online for immediate review. This ensures you can perform thorough forensic analysis over the past year while still having the most recent logs readily accessible for ongoing security monitoring. Longer retention is allowed, but not required by the standard, and options that propose shorter periods don’t meet the minimum, while an indefinite retention approach goes beyond the specified minimum.

Auditing and monitoring require a balance between keeping enough history for investigations and having recent activity ready for quick review. PCI DSS mandates that audit trail history be retained for at least one year, with a minimum of three months of that history available online for immediate review. This ensures you can perform thorough forensic analysis over the past year while still having the most recent logs readily accessible for ongoing security monitoring. Longer retention is allowed, but not required by the standard, and options that propose shorter periods don’t meet the minimum, while an indefinite retention approach goes beyond the specified minimum.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy