PCI ISA LATEST
Verify that the storage location security is reviewed at least _________
to confirm that backup media storage is secure. - ANSWERS-annually
Review media inventory logs to verify that logs are maintained and
media inventories are performed at least _____________ - ANSWERS-
annually
reviewing the following at least __________, either manually or via log
tools:
All security events
Logs of all system components that store, process, or transmit CHD
and/or SAD
Logs of all critical system components
Logs of all servers and system components that perform security
functions - ANSWERS-daily
reviewing logs of all other system components _______—either
manually or via log tools—based on the organization's policies and risk
management strategy. - ANSWERS-periodically
END OF
PAGE
1
, PCI ISA LATEST
retaining audit logs for at least _________, with a minimum of
________________ immediately available online - ANSWERS-one year
3 months
Implement processes to test for the presence of wireless access points
(802.11), and detect and identify all authorized and unauthorized
wireless access points on a _______________ basis - ANSWERS-
quarterly
Run internal and external network vulnerability scans at least _____ and
__________________ in the network - ANSWERS-quarterly and after
any significant change
verify that __________ internal/(external ASV) scans occurred in the
most recent _________ - ANSWERS-four quarterly
12-month period
penetration testing when?
END OF
PAGE
2
Verify that the storage location security is reviewed at least _________
to confirm that backup media storage is secure. - ANSWERS-annually
Review media inventory logs to verify that logs are maintained and
media inventories are performed at least _____________ - ANSWERS-
annually
reviewing the following at least __________, either manually or via log
tools:
All security events
Logs of all system components that store, process, or transmit CHD
and/or SAD
Logs of all critical system components
Logs of all servers and system components that perform security
functions - ANSWERS-daily
reviewing logs of all other system components _______—either
manually or via log tools—based on the organization's policies and risk
management strategy. - ANSWERS-periodically
END OF
PAGE
1
, PCI ISA LATEST
retaining audit logs for at least _________, with a minimum of
________________ immediately available online - ANSWERS-one year
3 months
Implement processes to test for the presence of wireless access points
(802.11), and detect and identify all authorized and unauthorized
wireless access points on a _______________ basis - ANSWERS-
quarterly
Run internal and external network vulnerability scans at least _____ and
__________________ in the network - ANSWERS-quarterly and after
any significant change
verify that __________ internal/(external ASV) scans occurred in the
most recent _________ - ANSWERS-four quarterly
12-month period
penetration testing when?
END OF
PAGE
2