What does PCI DSS require regarding service provider management?
- A.Organizations must maintain a list of service providers, have written agreements defining security responsibilities, and monitor service provider PCI DSS compliance status
- B.Only annual audits, because the standard treats a signed contract as evidence of a service provider's policy for SAQ A merchants in the year following a significant change
- C.No management needed, since the standard permits policy content to be inherited from a service provider unchanged for tokenized data stores once the CDE has been segmented
- D.Only signed contracts, an arrangement the standard blesses whenever the provider appears on a card brand registry, since registry listing substitutes for the customer's own due diligence and monitoring
Why A is correct
Organizations must list service providers, maintain written agreements defining security responsibilities, and monitor their ongoing PCI DSS compliance.
Know someone studying for PCI DSS? Send them this one.