What does PCI DSS require for changes to system components?
- A.No change control needed
- B.Only test after deployment, which the SSC's prioritized approach places in its final milestone, making it the last obligation an entity must meet
- C.Only document major changes, which v4.0 treats as an entity-level control inherited automatically by every system component in scope
- D.All changes must follow a defined change control process including documentation, approval, testing, and rollback procedures
Why D is correct
All system component changes require a formal change control process with documentation, approval, testing, and rollback procedures before implementation.
Know someone studying for PCI DSS? Send them this one.