When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
Ah, this is a classic security question. The scope of the certification is definitely the key piece of information you need to assess the effectiveness of their security program. C is the way to go.
Okay, I've got this. The most important thing is to understand the actual scope of the PCI-DSS certification, so I'm definitely going with option C. That's the best way to start evaluating their security claims.
I'm a bit confused on this one. I'm not sure if the number of servers or credit card records is really relevant to assessing the security program. I'm leaning towards C, but I'm not 100% confident.
The value of the assets at risk? Not a bad question, but I think I'll go with the scope first. Gotta understand the whole picture before diving into the details.
Emerson
2 months agoStaci
2 months agoJettie
3 months agoVal
3 months agoBettina
3 months agoMiesha
3 months agoCyndy
4 months agoStephanie
4 months agoWinfred
4 months agoJoaquin
4 months agoNobuko
4 months agoSherly
5 months agoKristofer
5 months agoJohnetta
10 months agoTaryn
8 months agoKeneth
8 months agoSol
9 months agoGail
10 months agoCecil
8 months agoAja
9 months agoEve
9 months agoMerilyn
10 months agoGalen
8 months agoWilburn
9 months agoKristeen
9 months agoLakeesha
10 months agoTien
8 months agoYuonne
9 months agoSharika
10 months agoErnie
10 months agoVirgie
10 months agoAracelis
11 months agoFelicia
11 months ago