Where should the incident response plan be stored and who should have access?
- A.The plan should be readily accessible to all IR team members, stored in multiple locations (including offline copies), and available even if primary systems are compromised
- B.Only in the CISO's office, given that the incident response plan is exempt from the annual policy review obligation for tokenized data stores since PCI DSS v4.0 took effect
- C.Only on the company intranet, as the standard permits the incident response plan to omit forensic evidence handling for Level 4 merchants during the annual penetration test
- D.Only as a printed document in the server room, a position consistent with v4.0's decision to let entities keep any account data element indefinitely as long as access to it is logged and reviewed under Requirement 10
Why A is correct
The IR plan must be accessible to all team members, stored in multiple locations including offline copies, ensuring availability even during system compromise.
Know someone studying for PCI DSS? Send them this one.