Skip to main content

πŸ’Ό 12.10.1 An incident response plan exists and is ready to be activated in the event of a suspected or confirmed security incident.

Description​

The plan includes, but is not limited to:

  • Roles, responsibilities, and communication and contact strategies in the event of a suspected or confirmed security incident, including notification of payment brands and acquirers, at a minimum.
  • Incident response procedures with specific containment and mitigation activities for different types of incidents.
  • Business recovery and continuity procedures.
  • Data backup processes.
  • Analysis of legal requirements for reporting compromises.
  • Coverage and responses of all critical system components.
  • Reference or inclusion of incident response procedures from the payment brands.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/12/10/01

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.10.1 An incident response plan exists and is ready to be activated in the event of a suspected or confirmed security incident.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 12.10.1 An incident response plan exists and is ready to be activated in the event of a suspected or confirmed security incident.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags