Mail containing payment cardholder data must be processed in a physically secure environment with appropriate access controls. True/False

Computer Science
Mail containing payment cardholder data must be processed in a physically secure environment with appropriate access controls. True/False

ScanSolve AI Answer

Answer

True

Step 1: Identify the relevant PCI DSS requirement.
PCI DSS Requirement 9 requires that physical access to cardholder data be restricted.

Step 2: Define sensitive areas.
Sensitive areas include any location that stores, processes, or transmits cardholder data, such as areas where mail containing payment cardholder data is handled or opened.

Step 3: Apply the requirement to the statement.
Physical access to these sensitive areas must be controlled at all times with appropriate security measures (PCI DSS 9.1.1). Therefore, mail containing payment cardholder data must be processed in physically secure areas.

True
True

Was this helpful?

Still stuck on this one?

Ask a follow-up, and the answer starts from this question.

Got a different question?Ask your own question