I vaguely recall something about self-assessment questionnaires, but I can't remember if that's the CISO's responsibility or more for the business units.
I like option C - the CISO should ensure the internal scope validation is completed and that an assessment is done to discover all credit card data. That seems like a critical step in the process.
Okay, I think the key here is that the CISO needs to work closely with a QSA to determine the appropriate scope. The CISO can't just rely on the business units' suggestions alone.
Hmm, I'm not entirely sure about this one. The CISO's role in PCI scoping isn't something I'm super familiar with. I'll need to review the PCI requirements more closely.
Option B is the way to go. I mean, who else would you trust with scoping the PCI environment other than a QSA? The CISO is not a mind reader, you know.
Carey
4 months agoEmelda
5 months agoDorthy
5 months agoEdward
5 months agoJamal
5 months agoCiara
6 months agoEttie
6 months agoTony
6 months agoCorazon
6 months agoHaley
6 months agoCatalina
6 months agoNicolette
6 months agoLeonida
6 months agoHolley
11 months agoJulio
10 months agoSharmaine
10 months agoCarlee
10 months agoMee
11 months agoSol
11 months agoEttie
10 months agoLon
10 months agoAlline
11 months agoKayleigh
11 months agoJennifer
10 months agoGlynda
10 months agoNan
10 months agoAide
12 months agoMarla
11 months agoTiera
11 months agoJosue
12 months agoAnabel
1 year agoReuben
1 year ago