PCIP Assessment Procedures & Reporting Obligations 5 — Questions and Answers
Question 1: A QSA discovers during an assessment that the merchant's previous ROC contained inaccurate findings. What is the appropriate course of action?
- Ignore the prior ROC and only document current findings
- Report the discrepancy to the PCI SSC's QSA Quality Assurance program (Correct answer)
- Amend the prior ROC retroactively
- Instruct the merchant to self-correct the previous submission
Correct answer: Report the discrepancy to the PCI SSC's QSA Quality Assurance program
Concerns about inaccurate prior ROCs should be escalated to the PCI SSC's QSA Quality Assurance program, which oversees QSA performance and report accuracy.
Question 2: Under PCI DSS, how long must an entity retain documentation related to a completed assessment (ROC, AOC, supporting evidence)?
- 6 months
- 1 year
- At least 1 year, with some evidence retained longer per policy (Correct answer)
- 5 years
Correct answer: At least 1 year, with some evidence retained longer per policy
PCI DSS requires policies and procedures to be retained for at least 12 months, and entities should retain assessment documentation for at least the same period to support audit trails.
Question 3: A service provider is listed on Visa's Global Registry of Service Providers. What does this listing confirm?
- The service provider has never experienced a data breach
- The service provider has validated compliance with PCI DSS (Correct answer)
- The service provider is exempt from annual ASV scans
- The service provider's employees have passed background checks
Correct answer: The service provider has validated compliance with PCI DSS
Visa's Global Registry of Service Providers lists entities that have validated their PCI DSS compliance, providing merchants a way to verify their vendors' compliance status.
Question 4: Which scenario correctly describes when a 'Not Applicable' (N/A) designation is permitted in a PCI DSS assessment?
- When the merchant decides a requirement is too costly to implement
- When a requirement genuinely does not apply due to the entity's environment or business model (Correct answer)
- When a compensating control has been approved by the acquirer
- When the requirement was marked N/A in the previous year's assessment
Correct answer: When a requirement genuinely does not apply due to the entity's environment or business model
N/A is only appropriate when a PCI DSS requirement cannot logically apply to the entity's environment—for example, a wireless security requirement for an entity with no wireless infrastructure.
Question 5: What is the primary purpose of the PCI DSS Attestation of Compliance (AOC) document?
- To summarize all vulnerabilities found during the assessment
- To formally attest that the entity completed the assessment and the results are accurate (Correct answer)
- To document compensating controls in detail
- To serve as the contract between the QSA and the assessed entity
Correct answer: To formally attest that the entity completed the assessment and the results are accurate
The AOC is a formal declaration signed by both the QSA (or ISA) and an officer of the entity, attesting that the assessment was completed and results accurately reflect the entity's compliance status.
Question 6: A merchant discovers mid-year that a previously compliant system has fallen out of compliance due to a software update. What reporting obligation applies?
- Wait until the next annual assessment to document the non-compliance
- Immediately notify the acquirer and work to remediate the non-compliant control (Correct answer)
- Self-certify the system as compliant pending a patch
- Submit an updated SAQ reflecting only passing requirements
Correct answer: Immediately notify the acquirer and work to remediate the non-compliant control
Merchants must maintain continuous compliance; discovering non-compliance between assessments requires notifying the acquirer and initiating remediation promptly.
Question 7: Which PCI DSS testing procedure requires both a review of firewall rule sets AND active testing to confirm cardholder data cannot traverse unauthorized paths?
- Vulnerability scanning
- Network segmentation testing (Correct answer)
- File integrity monitoring review
- Log review procedures
Correct answer: Network segmentation testing
Network segmentation testing requires both reviewing firewall configurations/rule sets and actively testing (e.g., penetration testing) to confirm segmentation is functioning as intended.
A QSA discovers during an assessment that the merchant's previous ROC contained inaccurate findings.
What is the appropriate course of action?