12.10 Suspected and confirmed incidents are responded to
How to meet it
Maintain and test an incident response plan covering card-data incidents.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 12.10, in plain English.
12.10.1An incident response plan exists and is ready to activate, covering roles, communication, containment, recovery, and legal reporting.
12.10.2The incident response plan is reviewed, updated, and tested at least every 12 months.
12.10.3Specific personnel are available 24/7 to respond to suspected or confirmed incidents.
12.10.4Incident responders are trained periodically on their responsibilities.
12.10.4.1The training frequency is defined in the targeted risk analysis.
12.10.5The plan includes monitoring and responding to alerts from security monitoring systems.
12.10.6The plan is evolved according to lessons learned and industry developments.
12.10.7Procedures are initiated when stored PAN is found where not expected.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Information security roles and responsibilitiesUse for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy mapBack to Requirement 12, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.