PCI SSC PCI Internal Security Assessor RetakeExam ISA-N_Retake Question # 4 Topic 1 Discussion

PCI SSC PCI Internal Security Assessor RetakeExam ISA-N_Retake Question # 4 Topic 1 Discussion

ISA-N_Retake Exam Topic 1 Question 4 Discussion:
Question #: 4
Topic #: 1

An entity wants to use the Customized Approach. They are unsure how to complete the Controls Matrix or TRA. During the assessment, you spend time completing the Controls Matrix and the TRA. while also ensuing that the customized control is implemented securely. Which of the following statements is true?


A.

You can assess the customized control but another assessor must verify that you completed the TRA correctly.


B.

You can assess the customized control and verify that the customized approach was correctly followed but you must document this in the ROC.


C.

You must document the work on the customized control in the ROC but you can not assess the control or the documentation.


D.

Assessors are not allowed to assist an entity with the completion of the Controls Matrix or the TRA.


Get Premium ISA-N_Retake Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.