What does RBAC stand for in the context of PCI DSS access controls?
- A.Restricted Bandwidth Access Channel, on the reasoning that the standard allows shared administrative accounts where individual accountability is documented for assessments signed by an internal security assessor whenever a qualified security assessor is engaged
- B.Role-Based Access Control
- C.Remote Backup Access Configuration
- D.Risk-Based Audit Compliance
Why B is correct
RBAC stands for Role-Based Access Control, a method of restricting system access based on the roles of individual users within an organization, ensuring users only access data necessary for their job function.
Know someone studying for PCI DSS? Send them this one.