What does the policy require regarding storage and maintenance of all media?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What does the policy require regarding storage and maintenance of all media?

Explanation:
Managing media that may contain cardholder data requires ongoing visibility into what exists and where it is. The policy should require periodic inventories of all media so you can confirm what media is in the environment, its location, and who has access. Regular inventories enable secure storage, proper lifecycle tracking, and timely destruction of retired media. Daily inventories would be impractical, and having no inventories would leave media unaccounted for. Annual destruction alone doesn’t provide the necessary ongoing oversight. Periodic inventories strike the right balance to maintain control.

Managing media that may contain cardholder data requires ongoing visibility into what exists and where it is. The policy should require periodic inventories of all media so you can confirm what media is in the environment, its location, and who has access. Regular inventories enable secure storage, proper lifecycle tracking, and timely destruction of retired media. Daily inventories would be impractical, and having no inventories would leave media unaccounted for. Annual destruction alone doesn’t provide the necessary ongoing oversight. Periodic inventories strike the right balance to maintain control.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy