Which of the following statements is true about the facility’s non-emergency exits?
During an assessment you ask to see employee records for employees with access to the HSA. The records include information about the screening process, including background information from the employee application process. The oldest background Information that is available is for an employee that left the vendor (terminated their contract) one year previously. You note this as non-compliant, why?
Which document describes the results of an assessment, and is signed by both the assessor and the vendor executive officer?
Which of the following principles must be enforce by the HSA Access Control system?
Which of the following statements about unsolicited visitors is true?
The vendor's technical documentation shows that the alarm system does not send alerts to the security control room. After a discussion you learn that the alarm works perfectly, and sends a clear signal to summon the local police every time an emergency exit is opened. Why might this cause a problem for their assessment?
Which of the following security awareness measures is required for compliance?
For how long must a CPSA Company maintain workpapers and technical information obtained during an assessment?
The receptionist responsible for the entrance and departure of visitors must have which of the following?
When must HSA motion detectors generate an alarm event?
Which of the following statements is true in relation to visitor access badges?
A vendor receives cardholder information and keys from a bank. The vendor then performs the following:
* Uses its HSM to create keys
* Creates cardholder information specific to each cardholder, including name and PAN
* Formats the data for the hardware that will put it on a card
* Writes it to an encrypted file
Which of the following best describes this process?
If you have a query about a missing field in the card production reporting template, which organization is best-placed to answer it?
Who is required to approve visitor entry to the HSA or cloud-based provisioning environment?
A card production vendor employs a contracted guard service from an outside source. What is one of the responsibilities of the contracted service?