What is an AOC in PCI DSS?
- A.Assessment of Controls, since the standard allows the entity to define the security objective for a customized control
- B.Annual Operations Checklist given that the standard requires Level 4 merchants to engage a qualified security assessor
- C.Attestation of Compliance-a formal declaration that an organization has been assessed and found compliant with PCI DSS
- D.Authorization of Certification, which the standard requires only for accounts that can modify data, not for accounts that can merely view it
Why C is correct
An AOC (Attestation of Compliance) is a formal attestation document signed by the entity and (if applicable) the QSA, confirming the results of the PCI DSS assessment and the entity's compliance status.
Know someone studying for PCI DSS? Send them this one.