CAS-001 · Question #272
A wholesaler has decided to increase revenue streams by selling direct to the public through an on- line system. Initially this will be run as a short term trial and if profitable, will be expanded…
The correct answer is C. Transfer the initial risks by outsourcing payment processing to a third party service provider. Outsourcing payment processing to a qualified third party transfers both the PCI DSS compliance burden and the skills gap risk to a vendor already certified to handle them.
Question
Options
- ATransfer the risks to another internal department, who have more resources to accept the risk.
- BAccept the risks and log acceptance in the risk register. Once the risks have been accepted close
- CTransfer the initial risks by outsourcing payment processing to a third party service provider.
- DMitigate the risks by hiring additional IT staff with the appropriate experience and certifications.
How the community answered
(25 responses)- A8% (2)
- B20% (5)
- C68% (17)
- D4% (1)
Why each option
Outsourcing payment processing to a qualified third party transfers both the PCI DSS compliance burden and the skills gap risk to a vendor already certified to handle them.
Transferring the risk to another internal department does not eliminate either risk since the organization as a whole still bears the compliance and expertise burden.
Accepting and logging the risks as closed is inappropriate when viable mitigation options exist and the risks carry significant compliance and financial consequences.
Engaging a third-party payment processor transfers both identified risks - staff inexperience with secure card processing and the PCI DSS compliance exposure - to a provider that is already audited and certified for those requirements. This is the most effective short-term strategy because it removes the organization from the scope of certain PCI DSS controls while the trial runs. For a limited-duration trial, outsourcing avoids the cost and delay of building internal capability before validating the business model.
Hiring additional staff with certifications takes considerable time, does not immediately satisfy PCI DSS audit requirements, and overinvests resources in a short-term trial of unproven profitability.
Concept tested: Risk transfer through third-party outsourcing
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.