According to the PCI DSS v3.2.1 Quick Reference Guide1, any in-scope system except for those identified as not at risk from malware must have anti-malware solutions installed and configured according to best practices. This is one of the requirements for preventing malware infections that could compromise cardholder data.
Question # 18
If disk encryption is used to protect account data what requirement should be met for the disk encryption solution?
A.
Access to the disk encryption must be managed independently of the operating system access control mechanisms
B.
The disk encryption system must use the same user account authenticator as the operating system
C.
The decryption keys must be associated with the local user account database
D.
The decryption keys must be stored within the local user account database
when disk encryption is used to protect account data, access to the disk encryption must be managed independently of the operating system access control mechanisms, which means it should not be affected by changes in the operating system settings or permissions. This is one of the requirements for ensuring that disk encryption is secure and effective.