Which items must be included in an up-to-date list of devices per 9.9.1?

Study for the PCI Data Security Standard Exam. Master your knowledge with interactive flashcards and multiple-choice questions, each with hints and explanations. Prepare confidently for your certification test!

Multiple Choice

Which items must be included in an up-to-date list of devices per 9.9.1?

Explanation:
The requirement tests maintaining an up-to-date inventory of devices that touch or connect to the cardholder data environment, with enough detail to uniquely identify each device and its location. Including make, model, location, and a serial number or other unique ID gives you a complete, actionable record: you know what the device is, where it’s deployed, and exactly which unit it is. Make and model show the type of hardware, location pins down where it sits for physical security and incident response, and the serial number or unique ID lets you distinguish between identical devices and track their lifecycle and maintenance. Make and model alone can’t tell you where to find the device or distinguish between units; location alone doesn’t identify the device itself; including serial number without location misses where the device is physically situated, which is important for access control and quick remediation.

The requirement tests maintaining an up-to-date inventory of devices that touch or connect to the cardholder data environment, with enough detail to uniquely identify each device and its location. Including make, model, location, and a serial number or other unique ID gives you a complete, actionable record: you know what the device is, where it’s deployed, and exactly which unit it is. Make and model show the type of hardware, location pins down where it sits for physical security and incident response, and the serial number or unique ID lets you distinguish between identical devices and track their lifecycle and maintenance.

Make and model alone can’t tell you where to find the device or distinguish between units; location alone doesn’t identify the device itself; including serial number without location misses where the device is physically situated, which is important for access control and quick remediation.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy