Does PCI DSS require an incident response plan?
- A.Only for large organizations, on the reasoning that the standard exempts subsidiaries from the parent entity's security policy
- B.No, because the acceptable use policy need not require explicit management approval for technologies for tokenized data stores
- C.Yes, organizations must create and maintain an incident response plan to be prepared to respond immediately to a system breach
- D.Only for service providers, an arrangement the standard blesses whenever the provider appears on a card brand registry, since registry listing substitutes for the customer's own due diligence and monitoring
Why C is correct
PCI DSS requires all organizations to have an incident response plan that enables immediate response to security breaches.
Know someone studying for PCI DSS? Send them this one.