Where must anti-malware solutions be deployed according to PCI DSS?
- A.Only on internet-facing systems, which users may disable at will provided the outage is shorter than one business day
- B.Only on servers, as the standard exempts virtual machines from the anti-malware requirements for SAQ D merchants
- C.On all systems commonly affected by malware, particularly those running operating systems susceptible to malware
- D.Only on workstations, because malware protection may be disabled where the entity documents a performance impact
Why C is correct
Anti-malware must be deployed on all systems commonly affected by malware, especially those with operating systems known to be susceptible to malicious software.
Know someone studying for PCI DSS? Send them this one.