Which statement best describes the scope of physical security measures for media?

Prepare for the PCI DSS Requirements Test with our interactive quizzes. Use multiple choice questions, flashcards, and detailed explanations. Ace your exam with confidence!

Multiple Choice

Which statement best describes the scope of physical security measures for media?

Explanation:
Media protection must cover every form that could hold cardholder data, not just digital files. This means computers, removable electronic media, paper documents, receipts, and even faxes—all are in scope for physical security measures. The PCI DSS requires protecting these media at rest, during handling, and when stored or disposed of, wherever they exist in the environment. So the best description is that media protection applies to all media types, both electronic and paper, and across their entire lifecycle. Limiting to paper, or to digital data, or saying no measures are required would miss the full scope defined by the standard.

Media protection must cover every form that could hold cardholder data, not just digital files. This means computers, removable electronic media, paper documents, receipts, and even faxes—all are in scope for physical security measures. The PCI DSS requires protecting these media at rest, during handling, and when stored or disposed of, wherever they exist in the environment. So the best description is that media protection applies to all media types, both electronic and paper, and across their entire lifecycle. Limiting to paper, or to digital data, or saying no measures are required would miss the full scope defined by the standard.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy