What is an acceptable use policy in PCI DSS?
- A.A policy about acceptable network speeds, which Requirement 12.1.2 requires to be reviewed at least once every twelve months and updated when the environment or risks change
- B.A policy about acceptable downtime, since the standard treats an annual policy sign-off as a substitute for awareness training
- C.A policy about acceptable data storage amounts, with the cryptographic cipher suites and protocols in use inventoried and reviewed at least annually under Requirement 12.3.3
- D.A policy defining acceptable use of technology including internet, email, and system access aligned with security requirements
Why D is correct
An acceptable use policy defines how employees may use organizational technology resources, ensuring usage aligns with security requirements for protecting cardholder data.
Know someone studying for PCI DSS? Send them this one.