preview

Hsc300 Unit 3 Assignment

Satisfactory Essays

Yes, agree you will probably not see such a fundamental security concept highlighted/spelled-out. Auditors typically ask for Business Justification, Executive Team Approval, and for the Merchant (NCDOT) to demonstrate Compensating Controls such as an active Data Loss Prevention (DLP) system is these situations (if utilized).

Again I am not stating that webmail cannot be utilized, simply that certain measures should be undertaken to ensure that RISK to the organization are either Mitigated, Compensating Controls put in-place, or that Risk Acceptance is understood by the Executive Team, etc. and documented for PCI Auditors.

Currently, I am preparing NCDOT for our Mandatory Annual PCI Audit. The Official Kickoff is Monday, August 31, 2015.

Get Access