What is the required destruction method for hard-copy materials containing CHD?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What is the required destruction method for hard-copy materials containing CHD?

Explanation:
For hard-copy materials containing cardholder data, the data must be made unreadable and unusable through destruction. The approved methods—cross-cut shredding, incineration, or pulping—physically destroy the documents so they cannot be reconstructed. Cross-cut shredding cuts the paper into small, confetti-like pieces, which makes reconstruction impractical. Incineration reduces the material to ash, and pulping disrupts the fibers, both preventing recovery of the data. Other options don’t meet the requirement. Burning in a non-controlled environment is unsafe and uncontrolled, so it’s not an acceptable method. Degaussing applies to magnetic storage, not paper, so it doesn’t affect CHD on hard copies. A regular home shredder that doesn’t cross-cut may leave readable strips or chunks and could be reconstructible, which isn’t adequate for PCI DSS destruction requirements.

For hard-copy materials containing cardholder data, the data must be made unreadable and unusable through destruction. The approved methods—cross-cut shredding, incineration, or pulping—physically destroy the documents so they cannot be reconstructed. Cross-cut shredding cuts the paper into small, confetti-like pieces, which makes reconstruction impractical. Incineration reduces the material to ash, and pulping disrupts the fibers, both preventing recovery of the data.

Other options don’t meet the requirement. Burning in a non-controlled environment is unsafe and uncontrolled, so it’s not an acceptable method. Degaussing applies to magnetic storage, not paper, so it doesn’t affect CHD on hard copies. A regular home shredder that doesn’t cross-cut may leave readable strips or chunks and could be reconstructible, which isn’t adequate for PCI DSS destruction requirements.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy