An organization has implemented a change-detection mechanism on their systems. How often must critical file comparisons be performed?
According to the glossary, "bespoke and custom software" describes which type of software?
Which of the following is true regarding compensating controls?
An entity is using custom software in their CDE. The custom software was developed using processes that were assessed by a Secure Software Lifecycle assessor and found to be fully compliant with the Secure SLC standard. What impact will this have on the entity's PCI DSS assessment?
An organization wishes to implement multi-factor authentication for remote access, using the user's individual password and a digital certificate. Which of the following scenarios would meet PCI DSS requirements for multi-factor authentication?
Which scenario describes segmentation of the cardholder data environment (CDE) for the purposes of reducing PCI DSS scope?
Could an entity use both the Customized Approach and the Defined Approach to meet the same requirement?
Passwords for default accounts and default administrative accounts should be?