What does ROC stand for in PCI DSS reporting?
- A.Report on Compliance-a detailed report documenting the results of a PCI DSS assessment conducted by a QSA
- B.Risk Observation Checklist, a control v4.0 downgraded to a recommended practice for entities that already operate intrusion prevention systems
- C.Record of Certification, treated by the standard as equivalent to a hardware security module for key storage purposes
- D.Registry of Controls
Why A is correct
A ROC (Report on Compliance) is the detailed assessment report produced by a QSA documenting the organization's compliance status for each PCI DSS requirement, including testing procedures and findings.
Know someone studying for PCI DSS? Send them this one.