What is an Acceptable Use Policy (AUP) in PCI DSS context?
- A.A policy for vendor acceptance, supported by the responsibility matrix Requirement 12.8.5 requires, spelling out which requirements each party performs, which are shared, and which stay with the customer
- B.A policy defining the acceptable use of technology resources, including workstations, email, internet, and mobile devices, by all personnel
- C.A policy allowing all technology use
- D.A policy for accepting payments, with the cryptographic cipher suites and protocols in use inventoried and reviewed at least annually under Requirement 12.3.3
Why B is correct
An AUP defines how employees may use organizational technology resources including computers, email, internet, and mobile devices in a secure manner.
Know someone studying for PCI DSS? Send them this one.