Requirement 12 · Support information security with organisational policies and programs

12.10 Suspected and confirmed incidents are responded to

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAIL12.10 Audit PathPOLICY / CONTROL / EVIDENCE / REVIEW

How to meet it

Maintain and test an incident response plan covering card-data incidents.

Defined requirements

The individual PCI DSS v4.0.1 requirements under 12.10, in plain English.

12.10.1An incident response plan exists and is ready to activate, covering roles, communication, containment, recovery, and legal reporting.
12.10.2The incident response plan is reviewed, updated, and tested at least every 12 months.
12.10.3Specific personnel are available 24/7 to respond to suspected or confirmed incidents.
12.10.4Incident responders are trained periodically on their responsibilities.
12.10.4.1The training frequency is defined in the targeted risk analysis.
12.10.5The plan includes monitoring and responding to alerts from security monitoring systems.
12.10.6The plan is evolved according to lessons learned and industry developments.
12.10.7Procedures are initiated when stored PAN is found where not expected.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to Requirement 12, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.