Which information should be maintained about service providers under 12.8.5?

Prepare for the PCI Data Security Standard Test with our quiz. Use flashcards and multiple-choice questions to learn each concept. Get ready to excel in your examination!

Multiple Choice

Which information should be maintained about service providers under 12.8.5?

Explanation:
Responsibility allocation for PCI DSS controls is what this item tests. When you rely on a service provider, you must clearly document which PCI DSS requirements are handled by the provider and which remain under your organization’s control. This clarity is essential for accountability, contract terms, and ongoing oversight, and it helps ensure there are no gaps where a control might be assumed to be covered by the other party. While practical details like contact information or language in the contract can be helpful, they do not establish the critical division of duties that 12.8.5 requires.

Responsibility allocation for PCI DSS controls is what this item tests. When you rely on a service provider, you must clearly document which PCI DSS requirements are handled by the provider and which remain under your organization’s control. This clarity is essential for accountability, contract terms, and ongoing oversight, and it helps ensure there are no gaps where a control might be assumed to be covered by the other party. While practical details like contact information or language in the contract can be helpful, they do not establish the critical division of duties that 12.8.5 requires.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy