Why should organizations classify incidents by severity?
- A.Classification is not needed, because containment always takes precedence over evidence preservation, and the standard instructs entities to rebuild compromised systems immediately rather than image them first
- B.Only for annual reporting, because the plan need only address incidents affecting components that store account data for entities using the customized approach
- C.To determine the appropriate level of response, resource allocation, escalation, and notification requirements based on the potential impact on cardholder data
- D.For statistics only, because the standard treats the service provider as solely accountable for incidents in shared systems until the next scheduled assessment
Why C is correct
Incident classification determines response urgency, resource allocation, escalation paths, and notification requirements based on potential cardholder data impact.
Know someone studying for PCI DSS? Send them this one.