Which of the following is required to be included in an incident response plan?
A.
Procedures for notifying PCI SSC of the security incident
B.
Procedures for responding to the detection of unauthorized wireless access points
C.
Procedures for securely deleting incident response records immediately upon resolution of the incident
D.
Procedures for launching a reverse-attack on the individual(s) responsible for the security incident
The Answer Is:
A
This question includes an explanation.
Explanation:
PCI DSS Requirement 12.10.1 requires entities to implement an incident response plan that includes roles, responsibilities, and communication and contact strategies for a data security incident, including notification of relevant payment brands1. This is important because each payment card brand has its own policies and procedures for dealing with a security breach, and failing to follow them or meet reporting deadlines could result in fines or loss of authority to process payment card transactions2. Therefore, an incident response plan must include procedures for notifying PCI SSC of the security incident, as well as any other entities that may require notification, whether by contract or law1. References:
Guidance for PCI DSS Scoping and Network Segmentation
Responding to a Cardholder Data Breach
Assessor_New_V4 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"