A vendor hosts virtual secure elements holding cardholder information in their data center. When a cardholder makes a purchase, the vendor creates a payment token which is sent to the cardholder’s mobile device. Which of the following best describes the vendor’s activities?
Which of the following statements is true in relation to visitor access badges?
During an assessment you do a walk-through of bringing card products into the HSA using the goods-tools trap. You act as production staff, using an empty cardboard box as the card products. During the process, the guard escorts you, along with the box, into the pre-press room. What is your conclusion?
A vendor is unsure which forms are needed to complete an assessment. Who should they ask?
Where can misprinted, partially finished cards be shredded?
If a vendor plans to terminate an employee, which of these must be done?
For how long must a vendor retain all applicant and employee background information on file?
Which of the following personnel changes must result in the vendor notifying the Vendor Program Administration (VPA)?
A vendor’s HSA access is enforced by a security turnstile they have a logical access-control system that ensures anti pass-back. The device is functioning correctly. When must the status of the access change?
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?