Incident Response Plan
PCIComplianceHubLast updated
A documented plan for detecting, containing, eradicating and recovering from a security incident, covering roles and responsibilities, communication paths, escalation, evidence handling and return to normal operation. PCI DSS Requirement 12.10 sets specific expectations: personnel must be available 24 hours a day, seven days a week to respond to alerts; the plan must be reviewed and tested at least once every 12 months; and it must cover notification of the payment brands and acquirers and the engagement of a PCI Forensic Investigator where account data may have been compromised. A plan that has never been exercised does not satisfy the requirement.