Security Incident Response Testing To Meet Audit Requirements
Introduction Incident response teams in enterprise environments beholden to regulatory requirements can conduct drills that will help satisfy auditors and keep their incident handlers sharp. A quick search through the latest PCI DSS, version 2.0, for the term “incident response” will reveal a number of requirements and testing procedures; following is a summary of those requirements. In particular, 12.9 states “implement an incident response plan. Be prepared to respond immediately to a system breach....