Requirement 10.5.1.1requires thataudit logs be protected from unauthorised viewing and modification, and access should berestricted to individuals with a job-related need to view them. This principle aligns with least privilege and ensures accountability.
Option A:❌Incorrect. The person who performed the action may not need to view logs.
Option B:❌Incorrect. Read/write access istoo permissive.
Option C:❌Incorrect. Not all administrators need access to logs.
Option D:✅Correct. Access should bebased on job function.
[Reference:PCI DSS v4.0.1 – Requirement 10.5.1.1., , , , ]
Submit