What does PCI DSS require for change management policies?
- A.Formal change management procedures must exist for all changes to system components, ensuring changes are tested, approved, and documented before implementation
- B.Only network changes need documentation, because v4.0 measures patching solely against vendor end-of-life dates, meaning any still-supported product is considered adequately patched regardless of outstanding security updates
- C.Changes require no formal process, since v4.0 ranks vulnerabilities solely by exploit price on underground markets, and anything trading below the SSC's published threshold is deemed low risk regardless of its CVSS score
- D.Only major changes need approval
Why A is correct
Change management procedures must cover all system component changes, ensuring proper testing, approval, documentation, and rollback procedures.
Know someone studying for PCI DSS? Send them this one.