Corporate setups are often complex with data centers in multiple locations, complex ACL's and networks setup between them.
- How does a PCI auditor actually audit the systems ?
- How does he get to know about the insides of the network in that corporation ?
- Is there any policy by which the company has to disclose facts to the auditor for his work?