Merchants 5 Step Guide
To PCI Compliance







 ISO / Acquirers 5 Step Guide
To PCI Compliance









 PCI COMPLIANCE
INFO









 PCI COMPLIANT
VENDORS


 About Us











Step 5: Perform a response audit after the event

Once the data breach is contained and letters sent to the affected customers, businesses, law enforcement and any other third-party entity, this is the time for all members of the rapid response team to document the data breach from beginning to end.

Each member of the team should maintain a log that contains the following information:
  • All information concerning the specific breach

  • All procedures followed, from the beginning to the containment and aftermath of the data breach.

  • Document any outsourcing to third-party companies, which took place during the breach, and add any documentation from said third-party concerning the data breach.

  • Document problem areas, if any, within your department.

  • Publish a list of any resources used during data breach notification, such as the FTC website, or other information and supply it to the rapid response team, customers and third party vendors.
Test rapid response plan

Periodically, your organization should practice utilizing the data breach plan from start to finish.

Since one of the most prevalent data breach incidents involves unsecured workstations, laptops, desktops, instruct your employees to properly secure all storage devices, etc.

Pay attention to IT issues, including monitoring your IDS systems. When is the last time you checked your IDS systems? When did you view logs of your Active Directory servers? Are you deleting employee user information, once the employee leaves the organization? Are you using encryption across all of your systems?

Routinely check everything at your organization, whether it's monthly, quarterly or yearly, as it relates to data transmission and storage.

pci compliance                      pci compliance asv


pci compliancePrint this page

Send this page to a friend

Data Breaches Part I
- Is it possible to prevent the inevitable?

Introduction

Step 1: A Good Defense is an Offense

Step 2: Perform a company-wide risk assessment/inventory

Step 3: Educate employees on breach/data security

Step 4: Create a pre-breach containment and communication plan

Step 5: Create a rapid response and internal audit/compliance team

Epilogue: Spend now or pay later

Introduction

New changes to PCI DSS Self Assessment Questionnaire

Step 1: Spot/investigate the breach

Step 2: Circle the wagons: Deploy the rapid response team

Step 3: Create a Notification Plan

Step 4: Implement the Notification/Communications Plan

Step 5: Perform a response audit after the event

Navigating state disclosure laws

Outsourcing data breach response to a third-party

Recommended reading
PCI Compliance Polls

Are you currently PCI Compliant?
Yes
No
Working towards compliance

Why are you looking at PCI Compliance
Required By Credit Card Processor
Required By Bank
Want to meet industry standards
Looking to secure network

What merchant level do you fall under for PCI Compliance?
Level 1
Level 2
Level 3
Level 4
I have no idea
View PCI Merchant Level Results
View All PCI Compliance Poll Results

EV SSL Certificate Guide

Sponsored Listing:

|  Home  |  About PCI Compliance |  For Acquirers |  Find PCI Compliance Solutions | 
|  Preventing Data Breaches |  Managing Data Breaches |  Contact Us |    EV SSL Certificate Guide | 
© 2008 PCI Compliance Guide.org
   All right reserved - do not copy any material without written permission.