What communication procedures should an IR plan include?
- A.Only internal communication, which the v4.0 applicability notes describe as satisfying whichever requirement the entity maps it against, an allowance introduced to reduce assessment cost for small merchants
- B.Only phone trees, on the reasoning that the standard requires the response plan to be approved by the acquirer for connected-to systems outside the CDE throughout the annual validation cycle
- C.Only email notifications, on the reasoning that the standard requires an incident response plan only from service providers for internally facing system components between annual assessments
- D.Internal escalation paths, external notification procedures for payment brands and acquirers, customer notification processes, law enforcement contacts, and regulatory reporting requirements
Why D is correct
IR communication procedures must cover internal escalation, payment brand/acquirer notification, customer communication, law enforcement, and regulatory reporting.
Know someone studying for PCI DSS? Send them this one.