medium
Single Answer
0

Kimon wants to validate his compliance with PCI-DSS. His company is a large commercial organization with millions of dollars in transactions a year. What is the most common method of conducting this type of testing for large organizations?

Answer Options

A

Self-assessment

B

To conduct a thirty-party assessment using COBIT

C

To partner with another company and trade assessments between the organizations

D

To conduct a third-party assessment using a qualified security assessor

Correct Answer: D

Explanation

Large organizations hire QSAs, or qualified security assessors, to conduct compliance checks. Third-party certification is required for large organizations by PCI-DSS, although smaller organizations can self-certify.