Epilogue: Spend now or pay later

Having a response plan and the rapid response team to carry out the plan will be the focal point of all information, if and when a data breach occurs. Having the tools in place before a data breach will determine whether an organization will survive the data breach and retain their customer base.

"Although it's difficult to make specific plans for an unspecified event, spending time now on your response plan can be a wise investment. It's always easier and faster to fine-tune your plan, should a breach occur, than to start from scratch. Ask anyone who has been through a data breach event - immediate action is critical to a successful response," wrote Beth Lynn, a vice president at First Data Corporation and the privacy officer for First Data Debit Services in Wilmington, Del., in an article entitled, "Are You Prepared for a Data Breach?"

PCI Compliance standards and an organization's security plan should work hand-in-hand, if an organization is cognizant that protecting customer data is not only a law in most states, it should be an internal standard at all times no matter the cost.

"While PCI compliance seems like another IT security headache, most of it is based in established security procedures and policies. And, with a lineup of well-known consultants, compliance can be integrated into a company's existing security program," wrote Dubin.

pci compliance                      pci compliance asv


pci compliancePrint this page

Send this page to a friend

Data Breaches Part I
- Is it possible to prevent the inevitable?

Introduction

Step 1: A Good Defense is an Offense

Step 2: Perform a company-wide risk assessment/inventory

Step 3: Educate employees on breach/data security

Step 4: Create a pre-breach containment and communication plan

Step 5: Create a rapid response and internal audit/compliance team

Epilogue: Spend now or pay later

Introduction

New changes to PCI DSS Self Assessment Questionnaire

Step 1: Spot/investigate the breach

Step 2: Circle the wagons: Deploy the rapid response team

Step 3: Create a Notification Plan

Step 4: Implement the Notification/Communications Plan

Step 5: Perform a response audit after the event

Navigating state disclosure laws

Outsourcing data breach response to a third-party

Recommended reading
PCI Compliance Polls

Are you currently PCI Compliant?
Yes
No
Working towards compliance

Why are you looking at PCI Compliance
Required By Credit Card Processor
Required By Bank
Want to meet industry standards
Looking to secure network

What merchant level do you fall under for PCI Compliance?
Level 1
Level 2
Level 3
Level 4
I have no idea
View PCI Merchant Level Results
View All PCI Compliance Poll Results

EV SSL Certificate Guide

Sponsored Listing: