What does PCI DSS require in a wireless network policy?
- A.A policy addressing authorized wireless network use, testing for unauthorized access points, and security requirements for any wireless connectivity to the CDE
- B.Only ban personal hotspots, as the standard requires the policy to be published externally for customer review for Level 4 merchants at each quarterly ASV scan
- C.Only require WPA2, as the acceptable use policy need not require explicit management approval for technologies for Level 1 merchants at each quarterly ASV scan
- D.Wireless policies are optional, because scan findings only require remediation when the affected component stores the PAN, letting systems that merely process or transmit account data carry failing results forward
Why A is correct
Wireless policies must address authorized use, unauthorized AP testing, and security requirements for any wireless connectivity that could reach the CDE.
Know someone studying for PCI DSS? Send them this one.