What does PCI require for monitoring access to sensitive areas under 9.1.1?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

What does PCI require for monitoring access to sensitive areas under 9.1.1?

Explanation:
PCI DSS requires ongoing monitoring of who can enter areas where cardholder data is processed or stored, and it also requires keeping the monitoring records for a defined period. The correct approach is to use video cameras and/or access-control systems to track individual physical access to those sensitive areas, with the resulting monitoring data retained for at least three months. This combination ensures both the ability to verify who accessed restricted spaces and sufficient time to review incidents or anomalies. The other options don’t fit because they weaken or ignore these requirements: monitoring is not optional, it must cover sensitive areas (not just non-sensitive ones), and there isn’t a prohibition on video monitoring in public areas—rather, monitoring and retention are what PCI DSS calls for.

PCI DSS requires ongoing monitoring of who can enter areas where cardholder data is processed or stored, and it also requires keeping the monitoring records for a defined period. The correct approach is to use video cameras and/or access-control systems to track individual physical access to those sensitive areas, with the resulting monitoring data retained for at least three months. This combination ensures both the ability to verify who accessed restricted spaces and sufficient time to review incidents or anomalies.

The other options don’t fit because they weaken or ignore these requirements: monitoring is not optional, it must cover sensitive areas (not just non-sensitive ones), and there isn’t a prohibition on video monitoring in public areas—rather, monitoring and retention are what PCI DSS calls for.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy