Which device-list detail is explicitly required by 9.9.1?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which device-list detail is explicitly required by 9.9.1?

Explanation:
Maintaining an accurate, auditable list of every device that processes, stores, or transmits cardholder data is essential. For this control, the list should include identifying details that let you uniquely recognize and manage each device: the make, model, location, and serial number. These details enable precise tracking, assignment, and replacement if needed, and they support security activities like inventory verification and incident response. Details like color and size don’t help identify or manage devices in a PCI DSS context, and purchase date or warranty status aren’t required by this requirement. The key goal is to know exactly which devices exist, where they are, and how to uniquely identify them for ongoing governance and risk management.

Maintaining an accurate, auditable list of every device that processes, stores, or transmits cardholder data is essential. For this control, the list should include identifying details that let you uniquely recognize and manage each device: the make, model, location, and serial number. These details enable precise tracking, assignment, and replacement if needed, and they support security activities like inventory verification and incident response.

Details like color and size don’t help identify or manage devices in a PCI DSS context, and purchase date or warranty status aren’t required by this requirement. The key goal is to know exactly which devices exist, where they are, and how to uniquely identify them for ongoing governance and risk management.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy