PCI Incident Response & Data Breach Management — Questions and Answers
Question 1: What must a PCI-compliant incident response plan include?
- Roles and responsibilities, communication procedures, containment strategies, forensic investigation steps, and recovery procedures (Correct answer)
- Only a phone number for the IT department
- A plan to notify customers within one year
- Only a written apology template for affected customers
Correct answer: Roles and responsibilities, communication procedures, containment strategies, forensic investigation steps, and recovery procedures
PCI DSS requires a documented incident response plan covering detection, containment, eradication, recovery, notification procedures, root cause analysis, and plan testing.
Question 2: What is the first priority during a payment data breach?
- Containing the breach to prevent further data loss while preserving evidence (Correct answer)
- Immediately notifying the media about the breach
- Deleting all evidence of the breach
- Shutting down all business operations permanently
Correct answer: Containing the breach to prevent further data loss while preserving evidence
Containment stops the bleeding by isolating affected systems, blocking attack vectors, and preserving forensic evidence, while maintaining business continuity where possible.
Question 3: What is a PCI Forensic Investigator (PFI)?
- A PCI Council-approved organization that investigates payment data breaches (Correct answer)
- A local police detective specializing in financial crimes
- Any cybersecurity consultant hired by the merchant
- A government agency that investigates all data breaches
Correct answer: A PCI Council-approved organization that investigates payment data breaches
PFIs are organizations approved by the PCI SSC to conduct forensic investigations of payment card data compromises, determining breach scope, timeline, and root cause.
Question 4: What notification requirements apply after a payment data breach?
- Notify payment brands, acquiring bank, and affected individuals as required by applicable breach notification laws (Correct answer)
- No notification is required if the breach is contained quickly
- Only notify the CEO of the affected organization
- Notification is only required for breaches affecting over 1 million records
Correct answer: Notify payment brands, acquiring bank, and affected individuals as required by applicable breach notification laws
Breach notification requirements vary by jurisdiction but generally require notifying card brands, acquiring banks, affected individuals, and potentially state attorneys general within specified timeframes.
Question 5: How often should the incident response plan be tested?
- At least annually through tabletop exercises or simulated incidents (Correct answer)
- Testing is not required once the plan is documented
- Only after an actual breach occurs
- Every five years during PCI recertification
Correct answer: At least annually through tabletop exercises or simulated incidents
PCI DSS requires annual testing of the incident response plan to ensure team members understand their roles and the plan effectively addresses potential breach scenarios.
Question 6: What is the role of log monitoring in detecting security incidents?
- Continuous review of system, network, and application logs to identify suspicious activity indicating a potential breach (Correct answer)
- Monitoring the physical log books at building entrances
- Tracking shipments of lumber products
- Recording employee work hours for payroll
Correct answer: Continuous review of system, network, and application logs to identify suspicious activity indicating a potential breach
Log monitoring involves collecting, centralizing, and analyzing logs from firewalls, IDS/IPS, servers, and applications to detect anomalous activity that may indicate an attack or breach.
What must a PCI-compliant incident response plan include?