Compromise

Also: Data compromise, Data breach

PCIComplianceHubLast updated

An intrusion into a system where unauthorised disclosure, theft, modification or destruction of cardholder data is suspected. The Council uses compromise, data compromise and data breach interchangeably, and 'suspected' is deliberate: the response obligations begin before anything is confirmed.

Applies to. Every entity. Requirement 12.10 requires a plan for responding to one, and several controls name suspected compromise as a trigger.
Example. A monitoring alert shows an unknown script on the checkout page. Nothing is yet proven. Under 12.10.1 the incident response plan is activated on suspicion, the payment brands and acquirer are notified per its procedures, and the affected page is preserved for investigation.
Limits. Compromise triggers specific actions elsewhere in the standard: a credential is changed on suspected compromise (8.3.8), a system account's password likewise (8.6.3), keys are replaced when their integrity is weakened or compromise is suspected (3.7.5), and wireless keys are changed when personnel with knowledge of them leave (2.3.2). Investigation of a payment data compromise is normally carried out by a PCI Forensic Investigator engaged through the brands, not by the entity alone.
In PCI DSS v4.0.1. 12.10.1, 8.3.8, 3.7.5