I vaguely recall something about self-assessment questionnaires, but I can't remember if that's the CISO's responsibility or more for the business units.
I like option C - the CISO should ensure the internal scope validation is completed and that an assessment is done to discover all credit card data. That seems like a critical step in the process.
Okay, I think the key here is that the CISO needs to work closely with a QSA to determine the appropriate scope. The CISO can't just rely on the business units' suggestions alone.
Hmm, I'm not entirely sure about this one. The CISO's role in PCI scoping isn't something I'm super familiar with. I'll need to review the PCI requirements more closely.
Option B is the way to go. I mean, who else would you trust with scoping the PCI environment other than a QSA? The CISO is not a mind reader, you know.
Carey
3 months agoEmelda
3 months agoDorthy
3 months agoEdward
4 months agoJamal
4 months agoCiara
4 months agoEttie
4 months agoTony
4 months agoCorazon
5 months agoHaley
5 months agoCatalina
5 months agoNicolette
5 months agoLeonida
5 months agoHolley
10 months agoJulio
8 months agoSharmaine
8 months agoCarlee
8 months agoMee
10 months agoSol
10 months agoEttie
8 months agoLon
9 months agoAlline
9 months agoKayleigh
10 months agoJennifer
9 months agoGlynda
9 months agoNan
9 months agoAide
10 months agoMarla
10 months agoTiera
10 months agoJosue
10 months agoAnabel
11 months agoReuben
11 months ago