Which statement best describes the scope of physical security measures for media?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which statement best describes the scope of physical security measures for media?

Explanation:
Media protection must cover every form that could hold cardholder data, not just digital files. This means computers, removable electronic media, paper documents, receipts, and even faxes—all are in scope for physical security measures. The PCI DSS requires protecting these media at rest, during handling, and when stored or disposed of, wherever they exist in the environment. So the best description is that media protection applies to all media types, both electronic and paper, and across their entire lifecycle. Limiting to paper, or to digital data, or saying no measures are required would miss the full scope defined by the standard.

Media protection must cover every form that could hold cardholder data, not just digital files. This means computers, removable electronic media, paper documents, receipts, and even faxes—all are in scope for physical security measures. The PCI DSS requires protecting these media at rest, during handling, and when stored or disposed of, wherever they exist in the environment. So the best description is that media protection applies to all media types, both electronic and paper, and across their entire lifecycle. Limiting to paper, or to digital data, or saying no measures are required would miss the full scope defined by the standard.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy