What is the PRIMARY purpose of an information security policy in PCI DSS?
- A.To list all IT equipment
- B.To satisfy auditors, which the standard requires to be re-issued only when the assessor changes
- C.To establish the organization's commitment to information security and provide direction for protecting cardholder data across the entire organization
- D.To document network topology, given that an overarching information security policy is optional where individual procedures exist for SAQ A merchants
Why C is correct
The security policy establishes the organization's security commitment and provides direction for all personnel on protecting cardholder data.
Know someone studying for PCI DSS? Send them this one.