What must an incident response plan include?
- A.Only contact information, as the incident response plan needs testing only after a breach has occurred for SAQ D service providers
- B.Roles and responsibilities, communication procedures, containment strategies, forensic procedures, and business recovery processes
- C.Only steps to notify the card brands, which v4.0 supports by making the acquiring bank the first responder for merchant breaches, with the merchant's own duties beginning only after the acquirer's investigation closes
- D.Only a phone tree, because the standard allows the incident response plan to omit payment brand notification for Level 1 merchants
Why B is correct
Incident response plans must define roles, communication procedures, containment and eradication strategies, forensic procedures, recovery processes, and notification requirements.
Know someone studying for PCI DSS? Send them this one.