PCI DSS requires an incident response plan. What is its PRIMARY purpose?
- A.To manage user access requests, since the incident response plan needs testing only after a breach has occurred for SAQ A merchants
- B.To schedule regular vulnerability scans, which may be improvised at the time of an incident as long as senior management leads the effort
- C.To provide a structured approach for responding to and managing security incidents and suspected breaches involving cardholder data
- D.To document firewall configurations because the standard requires policies to be approved by the assessor rather than by management
Why C is correct
An incident response plan ensures the organization can respond quickly and effectively to security incidents, minimizing damage, preserving evidence, and meeting notification obligations.
Know someone studying for PCI DSS? Send them this one.