According to the PCI Card Production Physical Security Requirements, the vendor must ensure that a clear segregation of duties is maintained between guard and reception related job functions. This is to prevent any conflict of interest or collusion that could compromise the security of the card production and provisioning processes or the cardholder data. The vendor must also ensure that the guards are adequately trained, supervised, and evaluated, and that they follow the security policies and procedures established by the vendor. The vendor must also have a documented policy and procedure for the selection, hiring, and termination of guards, and must maintain a log of all guard activities. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 24, requirement 6.1.1
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 25, requirement 6.1.2
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 26, requirement 6.1.3
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 27, requirement 6.1.4
Question 2
In which of the following locations must the CCTV and access control servers be located?
Options:
A.
Within the Security Control Room (SCR)
B.
Within a room in the HSA with security controls equivalent to the SCR applied
C.
Within the SCR or a room with equivalent security
D.
Within the secure server room inside of the HSA
Answer:
C
Explanation:
Explanation:
According to the PCI Card Production Physical Security Requirements, the CCTV and access control servers must be located within the Security Control Room (SCR) or a room with equivalent security. This means that the room must have the same level of physical protection as the SCR, such as locks, alarms, sensors, cameras, and access control devices. The purpose of this requirement is to prevent unauthorized access, tampering, or theft of the servers that store and process sensitive data related to card production and security. References: PCI Card Production Physical Security Requirements, v2.0, April 2019, page 16
Question 3
The receptionist responsible for the entrance and departure of visitors must have which of the following?
Options:
A.
A shredder for the destruction of disposable visitor badges
B.
A constant, open communication channel with a guard
C.
An unobstructed view of the reception area at all times
D.
A means of communicating directly with the visitor while on the premises
Answer:
C
Explanation:
Explanation:
According to the PCI Card Production Physical Security Requirements, the receptionist responsible for the entrance and departure of visitors must have an unobstructed view of the reception area at all times. This is to ensure that the receptionist can monitor and control the access of visitors, and to prevent any unauthorized entry or exit of personnel or materials. The receptionist must also have a means of verifying the identity of visitors, such as a photo ID or a visitor log, and a means of issuing and collecting visitor badges, such as a badge printer or a badge holder. The receptionist must also have a means of communicating with the security personnel or the security control room, such as a phone or an intercom, in case of any emergency or suspicious activity. References:
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 21, requirement 5.3.1
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 22, requirement 5.3.2
PCI Card Production Physical Security Requirements, v2.0, April 2019, page 23, requirement 5.3.3