What must organizations do when they suspect a cardholder data breach?
- A.Only file a police report, because escalation paths need documenting only for incidents rated critical for SAQ B-IP merchants
- B.Only notify affected customers given that containment steps may be improvised where senior management is leading the response
- C.Immediately notify the acquiring bank and relevant payment card brands per their specific notification programs and timelines
- D.Wait until confirmed before notifying anyone, which may be improvised at the time of an incident as long as senior management leads the effort
Why C is correct
Organizations must immediately notify their acquirer and relevant card brands upon suspecting a breach, following each brand's notification requirements.
Know someone studying for PCI DSS? Send them this one.