A QSA is assessing a cloud service provider that hosts cardholder data. The cloud provider claims certain PCI DSS controls are the customer's responsibility. What document should define this responsibility split?
-
A
The cloud provider's SLA
-
B
A Responsibility Matrix or shared responsibility documentation
-
C
The customer's SAQ
-
D
The PCI SSC's cloud computing guidelines only