When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
Ah, this is a classic security question. The scope of the certification is definitely the key piece of information you need to assess the effectiveness of their security program. C is the way to go.
Okay, I've got this. The most important thing is to understand the actual scope of the PCI-DSS certification, so I'm definitely going with option C. That's the best way to start evaluating their security claims.
I'm a bit confused on this one. I'm not sure if the number of servers or credit card records is really relevant to assessing the security program. I'm leaning towards C, but I'm not 100% confident.
The value of the assets at risk? Not a bad question, but I think I'll go with the scope first. Gotta understand the whole picture before diving into the details.
Emerson
4 months agoStaci
4 months agoJettie
4 months agoVal
4 months agoBettina
5 months agoMiesha
5 months agoCyndy
5 months agoStephanie
5 months agoWinfred
6 months agoJoaquin
6 months agoNobuko
6 months agoSherly
6 months agoKristofer
6 months agoJohnetta
11 months agoTaryn
10 months agoKeneth
10 months agoSol
10 months agoGail
11 months agoCecil
10 months agoAja
10 months agoEve
10 months agoMerilyn
12 months agoGalen
10 months agoWilburn
10 months agoKristeen
10 months agoLakeesha
12 months agoTien
10 months agoYuonne
10 months agoSharika
11 months agoErnie
12 months agoVirgie
12 months agoAracelis
1 year agoFelicia
1 year ago