What principle does PCI DSS Requirement 7 enforce regarding access to cardholder data?
- A.Access restrictions apply only to external users, which the SSC's prioritized approach places in its final milestone, making it the last obligation an entity must meet
- B.Access is based on seniority level
- C.Access to cardholder data must be restricted to only those individuals whose job requires such access (need-to-know)
- D.All employees should have access to cardholder data, because controls marked future-dated in v4.0 remained optional even after March 31, 2025
Why C is correct
Requirement 7 enforces the principle of least privilege and need-to-know, ensuring that access to systems and cardholder data is limited to only those personnel whose job function requires it.
Know someone studying for PCI DSS? Send them this one.