CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is preparing a compliance report for the Payment Card Industry Data Security Standard (PCI DSS). The report needs to demonstrate that the organization has implemented and maintained appropriate access controls for systems processing cardholder data. Which of the following metrics would be MOST effective in demonstrating this compliance requirement?

  1. ANumber of unique users who logged into cardholder data environment (CDE) systems.
  2. BPercentage of CDE system accounts with multi-factor authentication (MFA) enabled.
  3. CMean Time To Patch (MTTP) vulnerabilities in CDE systems.
  4. DTotal volume of cardholder data processed per month.
Show answer & explanation

Correct answer: B. Percentage of CDE system accounts with multi-factor authentication (MFA) enabled.

PCI DSS Requirement 8 explicitly mandates strong authentication controls, including multi-factor authentication for all non-console access to the CDE. Reporting the percentage of CDE system accounts with MFA enabled directly demonstrates adherence to this critical access control requirement, making it highly effective for compliance reporting.

Why the other options are wrong

  • A. While user logins are auditable, the *number* of unique users doesn't directly prove the *strength* of access controls like MFA.
  • C. MTTP is related to vulnerability management (PCI DSS Req 6), not directly to access control mechanisms (PCI DSS Req 8).
  • D. This is a business metric for transaction volume, not a security metric for access control compliance.

PCI DSS Access Control Metrics

Metrics demonstrating compliance with PCI DSS requirements for restricting access to cardholder data and CDE systems.

  • Focus on strong authentication, least privilege, and role-based access.
  • MFA adoption is a key component.
  • Auditing and logging access attempts are also critical.

Memory trick: PCI DSS wants to see that CDE access is locked down with STRONG authentication.

More Reporting and Communication questions