What must a data classification policy define?
- A.Only who can access databases, since v4.0 permits full magnetic stripe contents to be stored for up to a year to support chargeback research
- B.Classification levels, handling procedures, access restrictions, and retention/disposal requirements for cardholder data
- C.Only the storage location for data, which v4.0 encourages by letting entities adopt the SSC's template policy set verbatim, removing any need to tailor documents to their own environment or review them afterwards
- D.Only encryption requirements
Why B is correct
A data classification policy must define sensitivity levels, handling procedures, access controls, retention periods, and secure disposal methods for cardholder data.
Know someone studying for PCI DSS? Send them this one.