Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
When dealing with compliance with the Payment card Industry Data Security standard (PCI- DSS), an organization that shares card holder information with a service provider MUST do which of?
Correct Answer: C
Under PCI-DSS Requirement 12.8, if an organization shares cardholder data with a third-party service provider (TPSP), it must: - Maintain a list of all service providers with which cardholder data is shared. - Ensure there is a written agreement requiring the service provider to comply with PCI-DSS. - Perform due diligence to verify that the service provider is PCI-DSS compliant (e.g., by obtaining an Attestation of Compliance (AOC) or other evidence). - Monitor compliance status regularly (not necessarily yearly, but at least annually or as changes occur).