A financial services company must store customer transaction data in a cloud that complies with PCI DSS. Which of the following is a primary requirement for the cloud environment?
PCI DSS mandates segmentation or compensating controls to isolate cardholder data.
Why this answer
PCI DSS requires segmentation or compensating controls to isolate cardholder data from other tenants. While encryption and testing are also required, segmentation is a key design requirement specific to multi-tenant environments. Public auditing of all access logs is not a requirement.