89.3k views
3 votes
As defined by PCI DSS Requirement 7, access to cardholder data should be restricted based on which principle?

User Shiny
by
8.1k points

1 Answer

5 votes

Final answer:

Access to cardholder data should be restricted based on the principle of least privilege.

Step-by-step explanation:

As defined by PCI DSS Requirement 7, access to cardholder data should be restricted based on the principle of least privilege.

The principle of least privilege states that individuals should only have access to the minimum amount of information necessary to perform their job duties.

This means that access to cardholder data should be limited to employees who require it to perform their job responsibilities, reducing the risk of unauthorized access and potential data breaches.

User KenHBS
by
7.6k points