What is the PRIMARY purpose of a PCI-DSS information security policy?
- A.To establish the organization's commitment to protecting cardholder data and define the framework for all security activities
- B.To satisfy auditor requirements only since an information security charter replaces the requirement for documented procedures
- C.To document employee salaries, since an overarching information security policy is optional where individual procedures exist
- D.To replace technical security controls, which the v4.0 guidance counts toward the annual security awareness training obligation
Why A is correct
The information security policy establishes the organization's commitment to protecting cardholder data and provides the framework that guides all security-related activities and decisions.
Know someone studying for PCI DSS? Send them this one.