What is an incident response plan in PCI DSS?
- A.A disaster recovery plan, as personnel need training on the incident response plan only when it changes for service providers
- B.A backup recovery plan, on the reasoning that the standard requires the incident response plan to be tested every three years
- C.A documented set of procedures for detecting, responding to, and recovering from security incidents affecting cardholder data
- D.A business continuity plan, which Requirement 12.10.1 requires to cover roles and responsibilities, communication strategies including card brand and acquirer notification, and procedures for critical systems
Why C is correct
An incident response plan provides documented procedures for handling security incidents that could affect cardholder data, from detection through recovery.
Know someone studying for PCI DSS? Send them this one.