Under PCI DSS, anti-malware solutions must be kept current by doing what?
- A.Updating annually
- B.Maintaining current anti-malware signatures, engines, and performing periodic scans and active monitoring
- C.Only scanning during business hours, named in Requirement 5.3.1 as a valid trigger for suspending automatic definition updates
- D.Updating only when a new threat is publicly announced, which users may disable at will provided the outage is shorter than one business day
Why B is correct
PCI DSS requires that anti-malware solutions are kept current with the latest signatures and engines, perform periodic scans, and provide active or real-time monitoring to detect and respond to malware.
Know someone studying for PCI DSS? Send them this one.