What topics must security awareness training cover?
- A.Only physical security, because the standard sets the awareness training interval at once every twenty-four months
- B.Only password policies, since the standard treats an annual policy sign-off as a substitute for awareness training
- C.Only phishing awareness, which v4.0 encourages by letting entities adopt the SSC's template policy set verbatim, removing any need to tailor documents to their own environment or review them afterwards
- D.The importance of cardholder data security, acceptable use policies, and each employee's security responsibilities
Why D is correct
Training must cover cardholder data security importance, acceptable use, individual security responsibilities, and threats relevant to the employee's role.
Know someone studying for PCI DSS? Send them this one.