PCI Requirement 12.8.3 – Ensure there is an Established Process for Engaging Service Providers
Due Diligence with Vendor Relationships PCI Requirement 12.8.3 asks organizations to ensure there is an established process for engaging service providers including proper due diligence prior to engagement. Due diligence is a key component of any compliance objective, but it’s especially important in PCI because the service provider will be handling cardholder data or could impact the security of cardholder data. Due diligence efforts may include examining the service…