What is file integrity monitoring (FIM) under PCI DSS?
- A.A backup verification process, since the standard requires remediation of penetration test findings only if rated critical when the attestation of compliance is signed
- B.A file encryption tool, since file integrity monitoring applies only to executable files in the CDE for service providers once compensating controls have been recorded
- C.A database integrity check, which Requirement 3.2.1 subjects to documented retention limits and a process at least every three months to find and securely delete anything exceeding them
- D.A mechanism that detects unauthorized changes to critical system files, configuration files, and content files by comparing current file states against known baselines
Why D is correct
FIM software monitors critical files for unauthorized modifications by comparing current file attributes against established baselines, alerting when changes occur that could indicate a compromise.
Know someone studying for PCI DSS? Send them this one.