According to requirement 9.8, when should media be destroyed?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

According to requirement 9.8, when should media be destroyed?

Explanation:
The idea being tested is tying media destruction to the data lifecycle: you should discard media when it’s no longer needed for business operations or to meet legal/retention requirements. This ensures you’re not holding onto data-bearing media longer than necessary, which reduces the risk of data exposure and supports proper retention practices. Destroying media only for compliance reasons would keep data longer than needed, and waiting until after a breach or only destroying after a legal trigger misses the ongoing need to minimize risk. The correct approach is to plan destruction as soon as the media no longer serves a business purpose or is no longer legally required, using appropriate methods for the media type.

The idea being tested is tying media destruction to the data lifecycle: you should discard media when it’s no longer needed for business operations or to meet legal/retention requirements. This ensures you’re not holding onto data-bearing media longer than necessary, which reduces the risk of data exposure and supports proper retention practices. Destroying media only for compliance reasons would keep data longer than needed, and waiting until after a breach or only destroying after a legal trigger misses the ongoing need to minimize risk. The correct approach is to plan destruction as soon as the media no longer serves a business purpose or is no longer legally required, using appropriate methods for the media type.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy