PCI Requirement 12.10.2 – Review and Test the Plan at Least Annually
Testing Your Incident Response Plan You must test your incident response plan. What’s the point of the plan if you aren’t sure that it works? Without appropriate testing, major steps or gaps could be missed, which could result in increased exposure during a real incident. PCI requirement 12.10.2 states, “Review and test the plan, including all elements listed in Requirement 12.10.1, at least annually.” To verify compliance with PCI…