SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsPCI DSS Requirement 12.8.2 states that companies should maintain a written agreement with service providers that are responsible for the security of cardholder data the service provider possesses. Many people consider this requirement unnecessary or less important than most of the requirements. However, misunderstanding of this requirement may expose a company to serious liability. This paper intends to identify most of the risks a company may face when dealing with service providers. This paper provides sample clauses that an agreement should have in order to protect a company when dealing with other companies' cardholder data.