Which statement about the Attestation of Compliance (AOC) is correct?
Attestation of Compliance (AOC):
The AOC is a document that confirms an entity's compliance with PCI DSS requirements. It is signed by the entity (merchant or service provider) and the Qualified Security Assessor (QSA) if a QSA is involved.
Different AOC Templates:
PCI DSS provides distinct templates for service providers and merchants, tailored to their respective roles and responsibilities within the cardholder data environment (CDE).
Invalid Options:
B: PCI SSC does not sign AOCs; they are signed by the merchant/service provider and the QSA.
C: AOCs differ between ROCs and SAQs, so the same template is not universally used.
D: Both the merchant/service provider and the QSA/ISA (Internal Security Assessor) must sign the AOC when applicable.
Alica
10 months agoBelen
10 months agoRamonita
10 months agoCarin
10 months agoMarla
10 months agoJavier
11 months agoQuiana
11 months agoKent
11 months agoKatheryn
11 months agoCassi
11 months agoCammy
11 months agoLajuana
11 months agoDannie
11 months agoCaren
2 years agoBeatriz
2 years agoCaren
2 years agoSheron
2 years agoAdolph
2 years agoRosann
2 years agoHester
2 years agoLuis
2 years agoHershel
1 year agoLeonard
2 years agoNieves
2 years agoEladia
2 years agoGianna
2 years agoLeota
2 years agoMeaghan
2 years ago