A visitor log is used to record physical access to which locations?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

A visitor log is used to record physical access to which locations?

Explanation:
Recording who enters the building and the sensitive spaces inside is essential for protecting cardholder data. A visitor log should cover both the facility as a whole and the restricted areas where cardholder data is stored or transmitted, such as computer rooms and data centers. This provides accountability—knowing who came in, when, and for what purpose—so you can detect unauthorized access and trace any incidents back to an individual. Focusing only on the main entrance would miss entries into restricted zones; logging just outdoor parking or only data center elevators would leave gaps in visibility. The best practice is to maintain a visitor log that captures access to the entire facility and to the specific areas that house or process cardholder data.

Recording who enters the building and the sensitive spaces inside is essential for protecting cardholder data. A visitor log should cover both the facility as a whole and the restricted areas where cardholder data is stored or transmitted, such as computer rooms and data centers. This provides accountability—knowing who came in, when, and for what purpose—so you can detect unauthorized access and trace any incidents back to an individual.

Focusing only on the main entrance would miss entries into restricted zones; logging just outdoor parking or only data center elevators would leave gaps in visibility. The best practice is to maintain a visitor log that captures access to the entire facility and to the specific areas that house or process cardholder data.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy