Forensics
Also: Computer forensics
PCIComplianceHubLast updated
The use of investigative tools and analysis techniques to gather evidence from systems and determine how a compromise happened. For payment data compromises the work is normally done by a PCI Forensic Investigator, a firm the Council qualifies and the payment brands engage.
Applies to. Any entity that suffers or suspects a compromise of account data. The brands' rules decide when a PFI must be engaged; the entity's incident response plan decides what it does in the meantime.
Example. After a suspected checkout compromise, the entity preserves the web server images and logs rather than rebuilding, so that a PFI can establish what was taken, when, and how, which the brands need to decide on notification and liability.
Limits. Forensics after the fact depends on evidence kept beforehand: 10.5.1 requires twelve months of audit log history with three months immediately available, and 10.3 protects logs from alteration. An entity that rebuilds a compromised system before it is imaged has destroyed its own defence. A PFI investigation is not a PCI DSS assessment and its report is not a ROC.