medium
Single Answer
0Kimon wants to validate his compliance with PCI-DSS. His company is a large commercial organization with millions of dollars in transactions a year. What is the most common method of conducting this type of testing for large organizations?
Answer Options
A
Self-assessment
B
To conduct a thirty-party assessment using COBIT
C
To partner with another company and trade assessments between the organizations
D
To conduct a third-party assessment using a qualified security assessor
Correct Answer: D
Explanation
Large organizations hire QSAs, or qualified security assessors, to conduct compliance checks. Third-party certification is required for large organizations by PCI-DSS, although smaller organizations can self-certify.