Internal and external vulnerability scans should run at minimum on every __________ to meet requirement 11.2
In order to be considered a compensating control, which of the following must exist:
What are best practices for implementing PCI DSS into Business-as-Usual (BAU) Processes? (Select
ALL that apply)
Requirement 2.2.2 and 2.2.3 cover the use of secure services, protocols, and daemons as required for the function of a system. Which of the following is considered secure?
To be compliant with requirement 8.1.4 you have to remove/disable inactive user accounts at least every