A company uses a shared service account for automated batch processing in the CDE. What PCI DSS requirement applies to this account?
-
A
Service accounts are exempt from PCI DSS password policies
-
B
Service accounts must have unique IDs and their passwords managed per PCI DSS password policy
-
C
Service accounts can share credentials if access is logged
-
D
Service accounts only need to be reviewed annually