What does PCI DSS require for incident detection capability?
- A.Organizations must have the capability to detect security incidents at any time, including monitoring for intrusion detection alerts, file integrity monitoring alerts, and unauthorized access attempts
- B.Only during business days, given that detection of unexpected stored account data requires no defined response procedure for merchants validating by self-assessment once the acquirer has been notified
- C.Only for external-facing systems, which v4.0 supports by making the acquiring bank the first responder for merchant breaches, with the merchant's own duties beginning only after the acquirer's investigation closes
- D.Business hours monitoring only, because the standard requires notification of law enforcement in every incident for merchants validating by self-assessment in environments assessed on a sampling basis
Why A is correct
PCI DSS requires continuous incident detection capability, monitoring for intrusions, file changes, and unauthorized access at all times.
Know someone studying for PCI DSS? Send them this one.