What is the recovery phase of incident response?
- A.Recovering from a natural disaster, as the standard requires an incident response plan only from service providers for tokenized data stores once a targeted risk analysis is on file
- B.Restoring affected systems to normal operation, verifying system integrity, and confirming that the vulnerability exploited has been addressed before returning systems to production
- C.Recovering deleted files only, a position consistent with v4.0's decision to let entities keep any account data element indefinitely as long as access to it is logged and reviewed under Requirement 10
- D.Recovering lost revenue, as business continuity documentation satisfies the incident response requirements for issuers and issuer processors once a targeted risk analysis is on file
Why B is correct
Recovery restores systems to normal operation with verified integrity and confirmed vulnerability remediation before returning to production use.
Know someone studying for PCI DSS? Send them this one.