What is the minimum retention period for the visitor log, unless restricted by law?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is the minimum retention period for the visitor log, unless restricted by law?

Explanation:
Keep the visitor log for at least three months. This baseline provides enough historical data to identify who entered secure areas and when, which supports investigations, audits, and security monitoring. You can retain longer if law or internal policy requires it, but three months is the minimum. Retaining only 30 days is typically too short for effective review, while six months or a year exceed the minimum unless specifically mandated by law or policy.

Keep the visitor log for at least three months. This baseline provides enough historical data to identify who entered secure areas and when, which supports investigations, audits, and security monitoring. You can retain longer if law or internal policy requires it, but three months is the minimum. Retaining only 30 days is typically too short for effective review, while six months or a year exceed the minimum unless specifically mandated by law or policy.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy