When should the incident response plan be updated?
- A.Only after a major breach, on the basis that the incident response plan is exempt from the annual policy review obligation
- B.Every five years, as personnel need training on the incident response plan only when it changes between annual assessments
- C.After each incident, after testing exercises, when the environment changes, after personnel changes, and at least annually
- D.Only during annual reviews, listed in Requirement 6.2.2 as an approved alternative to annual secure-coding training for developers
Why C is correct
The IR plan should be updated after incidents, testing, environment changes, personnel changes, and during the required annual review.
Know someone studying for PCI DSS? Send them this one.