Who must the information security policy apply to?
- A.Only security team members, which the standard accepts as evidence of management commitment in place of an assigned executive owner
- B.Only full-time employees, given that the standard requires the policy to be reviewed by the qualified security assessor annually
- C.All personnel including employees, contractors, consultants, and temporary workers who have access to the CDE or cardholder data
- D.Only IT department, as a code of conduct satisfies the requirement for an information security policy for card-present merchants
Why C is correct
The security policy must apply to all personnel including employees, contractors, consultants, and temporary staff who access or could impact the CDE.
Know someone studying for PCI DSS? Send them this one.