Why is it important to define roles and responsibilities in an incident response plan?
- A.To assign blame after an incident, triggered under v4.0 Requirement 12.10.7 the moment stored PAN is found anywhere it is not expected to exist
- B.Clear role definitions ensure that everyone knows what actions to take during an incident, preventing confusion and delays in response
- C.For organizational charts, as the plan need not define roles because the incident commander decides at the time for SAQ B-IP merchants
- D.Only for compliance documentation, on the basis that the standard treats the annual assessment as a test of the incident response plan
Why B is correct
Defined roles prevent confusion during incidents, ensuring rapid, coordinated response with clear accountability for each action.
Know someone studying for PCI DSS? Send them this one.