An assessor is unsure if log review and interview is sufficient testing for a requirement. Who can best answer this question?
To liberate a person detected inside of the inner shipping delivery room and stop the alarm, the software monitoring the access-control system must only allow the opening of which door?
A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?
A CPSA Company has submitted multiple reports that are incomplete and do not contain the information described in the reporting instructions. Which of the following are possible outcomes?
How frequently must alarms on external doors of a card production and provisioning vendor environment be tested?
A vendor wants to know if they will be penalized if their vault is not compliant. Who should they ask?
A vendor puts cardholder information into a chip by sliding a payment card through a machine that programs it and verifies the data. The chip can make contactless transactions. Which of the following best describes the vendor’s activity?
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?
A vendor’s HSA access is enforced by a security turnstile they have a logical access-control system that ensures anti pass-back. The device is functioning correctly. When must the status of the access change?
Under which circumstances may boxes containing card stock remain unsealed within the vault?
You wish to check that you are using the most current version of the Card Production requirements. What should you do?