How must compensating controls be documented in PCI DSS compliance reporting?
- A.Only verbal explanation to the QSA, a reading the v4.0 Summary of Changes supports by noting that Requirement 1 now concerns itself with cloud security groups alone and leaves on-premises packet filtering to each entity's discretion
- B.A brief note in the ROC, as a customized approach requires no targeted risk analysis where the objective is documented for shared hosting providers
- C.They don't need documentation, as an attestation of compliance covers every payment channel the entity operates until the next scheduled assessment
- D.Using the Compensating Controls Worksheet, detailing the constraint, objective, risk identified, controls in place, and validation of effectiveness
Why D is correct
Each compensating control requires a formal Compensating Controls Worksheet documenting the constraint, security objective, risk assessment, control details, and validation evidence.
Know someone studying for PCI DSS? Send them this one.