What data classification requirement exists in PCI DSS security policies?
- A.Only classify as public or private, which Requirement 12.1.1 lists as an acceptable substitute for a formally published security policy
- B.Classification is optional, on the basis that an information security charter replaces the requirement for documented procedures
- C.Only classify network segments because security roles may be assigned informally without documentation for tokenized data stores
- D.A data classification policy must categorize data by sensitivity level to ensure cardholder data receives appropriate protection
Why D is correct
Data classification policies categorize data by sensitivity, ensuring cardholder data is identified and protected at the appropriate level throughout its lifecycle.
Know someone studying for PCI DSS? Send them this one.