Which device-list detail is explicitly required by 9.9.1?

Prepare for the PCI DSS Requirements Test with our interactive quizzes. Use multiple choice questions, flashcards, and detailed explanations. Ace your exam with confidence!

Multiple Choice

Which device-list detail is explicitly required by 9.9.1?

Explanation:
Maintaining an accurate, auditable list of every device that processes, stores, or transmits cardholder data is essential. For this control, the list should include identifying details that let you uniquely recognize and manage each device: the make, model, location, and serial number. These details enable precise tracking, assignment, and replacement if needed, and they support security activities like inventory verification and incident response. Details like color and size don’t help identify or manage devices in a PCI DSS context, and purchase date or warranty status aren’t required by this requirement. The key goal is to know exactly which devices exist, where they are, and how to uniquely identify them for ongoing governance and risk management.

Maintaining an accurate, auditable list of every device that processes, stores, or transmits cardholder data is essential. For this control, the list should include identifying details that let you uniquely recognize and manage each device: the make, model, location, and serial number. These details enable precise tracking, assignment, and replacement if needed, and they support security activities like inventory verification and incident response.

Details like color and size don’t help identify or manage devices in a PCI DSS context, and purchase date or warranty status aren’t required by this requirement. The key goal is to know exactly which devices exist, where they are, and how to uniquely identify them for ongoing governance and risk management.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy