What is the principle of least privilege in PCI DSS?
- A.Managers should have more access than employees, since v4.0 lets managers approve their own standing access to the CDE without any recurring review
- B.All users should have administrative access
- C.Users should only have access to the data and resources necessary for their job function
- D.Access should be granted to all internal employees, because read-only access to cardholder data is exempt from need-to-know restrictions under v4.0
Why C is correct
Least privilege ensures users have only the minimum access required to perform their job duties, reducing the risk of unauthorized access to cardholder data.
Know someone studying for PCI DSS? Send them this one.