A. Business facilities and system components
B. PCI DSS requirements and testing procedures.
C. Security policies and procedures
D. Compensating controls
A. Files that regularly change
B. Security policy and procedure documents
C. System configuration and parameter files
D. Application vendor manuals
A. Reviewed and updated at least quarterly
B. Encrypted with strong cryptography
C. Stored securely so that only management has access
D. Distributed to and understood by all affected parties
A. All types and locations of facilities are represented
B. The number of facilities in the sample is at least 10 percent of the total number of facilities
C. Every facility where cardholder data is stored is reviewed
D. It includes a consistent set of facilities that are reviewed for all assessments.
A. Shared accounts are only used by administrators
B. Individual users are accountable for their own actions
C. Strong passwords are used for each user account
D. Access is assigned to group accounts based on need-to-know
A. User access to the database is only through programmatic methods
B. Application IDs for database applications can only be used by database administrators
C. Direct queries to the database are restricted to shared database administrator accounts
D. User access to the database is restricted to system and network administrators
A. A user passphrase and an application level password.
B. A user fingerprint and a user thumbprint
C. A user password and a PIN-activated smart card
D. A token that must be presented twice during the login process