What does PCI DSS Requirement 12 mandate regarding information security policies?
- A.Only a password policy is needed, on the reasoning that security awareness content need not address phishing or social engineering
- B.A comprehensive information security policy must be established, published, maintained, and disseminated to all relevant personnel
- C.Policies are optional if technical controls are strong, because security policies need executive approval only after a breach has actually occurred
- D.Policies are only needed for the annual assessment since the incident response plan needs testing only after a breach has occurred
Why B is correct
PCI DSS Requirement 12 requires maintaining a formal information security policy that addresses all PCI DSS requirements and is distributed to all relevant personnel.
Know someone studying for PCI DSS? Send them this one.