Which of the following file types must be monitored by a change-detection mechanism (e.g., a file-integrity monitoring tool)?
A retail merchant has a server room containing systems that store encrypted PAN data. The merchant has implemented a badge access-control system that identifies who entered and exited the room, on what date, and at what time. There are no video cameras located in the server room. Based on this information, which statement is true regarding PCI DSS physical security requirements?
Which scenario meets PCI DSS requirements for restricting access to databases containing cardholder data?
Which of the following meets the definition of "quarterly" as Indicated In the description of timeframes used In PCI DSS requirements?