How long should the visitor log be retained, unless law requires otherwise?

Study for the PCI Data Security Standard Test. Utilize flashcards and multiple-choice questions, each offering hints and detailed explanations. Prepare thoroughly for your exam and ensure compliance with PCI DSS!

Multiple Choice

How long should the visitor log be retained, unless law requires otherwise?

Explanation:
The fundamental idea is to set a practical minimum retention window for visitor logs to support security review and incident response. Under PCI DSS, keeping visitor logs for a minimum period of 90 days (about three months) provides enough recent data to trace access to restricted areas and investigate events, while avoiding unnecessary long-term storage. If laws or regulations require a longer period, that would take precedence, but the standard baseline is three months. Retaining for six months or a year goes beyond the minimum and isn’t required by the standard, and keeping logs indefinitely introduces privacy and storage concerns. So the best choice is to retain the visitor log for a minimum of three months, unless law requires otherwise.

The fundamental idea is to set a practical minimum retention window for visitor logs to support security review and incident response. Under PCI DSS, keeping visitor logs for a minimum period of 90 days (about three months) provides enough recent data to trace access to restricted areas and investigate events, while avoiding unnecessary long-term storage. If laws or regulations require a longer period, that would take precedence, but the standard baseline is three months. Retaining for six months or a year goes beyond the minimum and isn’t required by the standard, and keeping logs indefinitely introduces privacy and storage concerns. So the best choice is to retain the visitor log for a minimum of three months, unless law requires otherwise.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy