What does Requirement 12.1.1 require?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

What does Requirement 12.1.1 require?

Explanation:
The main idea here is that the security policy must be kept current with the organization’s risks and environment. Requirement 12.1.1 says you should review the security policy at least once a year and update it whenever there are changes in the business, the environment, or risk posture. This keeps governance aligned with how the company operates and what threats and controls are in place. That’s why the correct choice is best: it matches the annual review and update-on-change requirement. Other options don’t fit because a quarterly review isn’t the stated minimum, updating only after a security incident isn’t proactive governance, and creating a brand-new policy every year regardless of changes is unnecessary and not required.

The main idea here is that the security policy must be kept current with the organization’s risks and environment. Requirement 12.1.1 says you should review the security policy at least once a year and update it whenever there are changes in the business, the environment, or risk posture. This keeps governance aligned with how the company operates and what threats and controls are in place.

That’s why the correct choice is best: it matches the annual review and update-on-change requirement. Other options don’t fit because a quarterly review isn’t the stated minimum, updating only after a security incident isn’t proactive governance, and creating a brand-new policy every year regardless of changes is unnecessary and not required.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy