When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
Ah, this is a classic security question. The scope of the certification is definitely the key piece of information you need to assess the effectiveness of their security program. C is the way to go.
Okay, I've got this. The most important thing is to understand the actual scope of the PCI-DSS certification, so I'm definitely going with option C. That's the best way to start evaluating their security claims.
I'm a bit confused on this one. I'm not sure if the number of servers or credit card records is really relevant to assessing the security program. I'm leaning towards C, but I'm not 100% confident.
The value of the assets at risk? Not a bad question, but I think I'll go with the scope first. Gotta understand the whole picture before diving into the details.
Emerson
5 months agoStaci
6 months agoJettie
6 months agoVal
6 months agoBettina
6 months agoMiesha
6 months agoCyndy
7 months agoStephanie
7 months agoWinfred
7 months agoJoaquin
7 months agoNobuko
7 months agoSherly
8 months agoKristofer
8 months agoJohnetta
1 year agoTaryn
12 months agoKeneth
12 months agoSol
12 months agoGail
1 year agoCecil
12 months agoAja
12 months agoEve
12 months agoMerilyn
1 year agoGalen
12 months agoWilburn
12 months agoKristeen
1 year agoLakeesha
1 year agoTien
12 months agoYuonne
12 months agoSharika
1 year agoErnie
1 year agoVirgie
1 year agoAracelis
1 year agoFelicia
1 year ago