CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

A payment card processor asks a merchant to submit formal documentation, signed by a qualified security assessor, confirming that all applicable PCI DSS requirements have been met during the assessment period. What is this document called?

  1. AAttestation of compliance
  2. BRisk register
  3. CRight-to-audit clause
  4. DMemorandum of understanding
Show answer & explanation

Correct answer: A. Attestation of compliance

An attestation of compliance (AOC) is a formal statement, typically signed by a qualified security assessor (QSA) or the organization itself, certifying that an assessment (such as PCI DSS) was completed and the entity meets the applicable requirements.

Why the other options are wrong

  • B. A risk register tracks identified risks, not compliance certification.
  • C. A right-to-audit clause grants the ability to audit a vendor, but is not itself the compliance certification.
  • D. An MOU documents mutual intent, not a compliance attestation.

Attestation of Compliance (AOC)

A formal document certifying that an organization has met the requirements of a specific compliance standard, often signed by an assessor.

  • Common in PCI DSS assessments
  • Signed by a Qualified Security Assessor (QSA) or self-assessed
  • Provides evidence to partners/regulators of compliance status

Memory trick: AOC = 'Assessor's Official Certificate' of compliance.

More Security Program Management and Oversight questions