What are the basic components of a PCI DSS incident response plan?
- A.Only a contact list, since the standard treats the annual assessment as a test of the incident response plan for SAQ C-VT merchants until the next scheduled assessment
- B.Roles and responsibilities, communication procedures, containment strategies, eradication and recovery procedures, evidence preservation, and lessons learned processes
- C.Only an escalation procedure, which v4.0 supports by making the acquiring bank the first responder for merchant breaches, with the merchant's own duties beginning only after the acquirer's investigation closes
- D.Only a notification template, on the basis that the incident response plan is exempt from the annual policy review obligation when the report on compliance is produced
Why B is correct
A complete IR plan includes roles/responsibilities, communication procedures, containment, eradication, recovery, evidence preservation, and lessons learned.
Know someone studying for PCI DSS? Send them this one.