authorization Dual control - ANSWER -least two people are required to perform any key -management operations and no one person has access to the authentication materials (for example, passwords or keys) of another Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor -supplied security patches. Install critical security patches within _____ of release. - ANSWER -one month entities monitor its service providers' PCI DSS compliance status at least ________ - ANSWER -
annually Evidence Retention It is recommended that the ISA secure and maintain digital and/or hard copies of case logs, audit results and work papers, notes, and any technical information that was created and/or obtained during the PCI Data Security Assessment for a minimum of ________ or as applicable to company data retention policies - ANSWER -of three (3) years Examine documented results of scope reviews and interview personnel to verify that the reviews are performed: - ANSWER -At least quarterly After significant changes to the in -scope environment For a sample of system components, inspect system configuration settings to verify that authentication parameters are set to require that user accounts be locked out after not more than ___________ invalid logon attempts. - ANSWER -6 For a sample of system components, inspect system configuration settings to verify that user password/passphrase parameters are set to require users to change passwords at least once every ______. - ANSWER -90 days idle time out features have been set to ________ - ANSWER -15 mins or less IDS/IPS where? - ANSWER -at perimeter of CDE and at crit points in CDE If you find a potential card number, you can use a ________ check to see if it is a valid card number - ANSWER -mod 10 (luhn) Implement processes to test for the presence of wireless access points (802.11), and detect and identify all authorized and unauthorized wireless access points on a _______________ basis - ANSWER -quarterly incident response plan tested when? - ANSWER -annually information security policy reviewed when? - ANSWER -annually and sig changes Installation of all applicable vendor -supplied security patches within an ___________________ - ANSWER -appropriate time frame (for example, within three months)