What must a written agreement with a service provider include under Req 12.8.2?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

What must a written agreement with a service provider include under Req 12.8.2?

Explanation:
This item tests how you formalize accountability with third-party providers. Under PCI DSS, a written agreement with a service provider must include an explicit acknowledgement that the provider is responsible for the security of cardholder data they possess, store, process, or transmit on behalf of the customer, or in any way that could affect the customer’s cardholder data environment. This makes security responsibilities clear in contract and ensures the provider cannot overlook protection of the data. Annual reports, exemptions from PCI DSS, or statements that the provider does not attest responsibility do not reflect this contract-based accountability requirement. The standard is about making security responsibility explicit in the agreement.

This item tests how you formalize accountability with third-party providers. Under PCI DSS, a written agreement with a service provider must include an explicit acknowledgement that the provider is responsible for the security of cardholder data they possess, store, process, or transmit on behalf of the customer, or in any way that could affect the customer’s cardholder data environment. This makes security responsibilities clear in contract and ensures the provider cannot overlook protection of the data.

Annual reports, exemptions from PCI DSS, or statements that the provider does not attest responsibility do not reflect this contract-based accountability requirement. The standard is about making security responsibility explicit in the agreement.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy