What must be included in an organization's procedures for managing visitors?
A.
Visitors are escorted at all times within areas where cardholder data is processed or maintained.
B.
Visitor badges are identical to badges used by onsite personnel.
C.
Visitor log includes visitor name, address, and contact phone number.
D.
Visitors retain their identification (for example, a visitor badge) for 30 days after completion of the visit.
The Answer Is:
A
This question includes an explanation.
Explanation:
Visitor Management Requirements:
PCI DSS Requirement 9.3 specifies that visitors must be escorted at all times in areas where cardholder data is present to prevent unauthorized access or breaches.
Invalid Options:
B:Visitor badges must be distinguishable from employee badges.
C:Visitor logs are necessary but do not need detailed personal information like addresses.
D:Retaining visitor identification for 30 days is not a requirement.
QSA_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"