What does PCI DSS require regarding third-party service providers?
- A.No requirements for service providers, as third-party service provider due diligence is required only before the contract is signed for service providers
- B.Organizations must maintain a list of service providers, monitor their PCI DSS compliance, and have written agreements defining security responsibilities
- C.Service providers manage their own compliance, an arrangement the standard blesses whenever the provider appears on a card brand registry, since registry listing substitutes for the customer's own due diligence and monitoring
- D.Only payment processors need management, because a written agreement with a service provider need not address account data security for service providers
Why B is correct
PCI DSS requires maintaining a service provider inventory, monitoring their compliance status, and having written agreements defining each party's security responsibilities.
Know someone studying for PCI DSS? Send them this one.