PCI DSS Requirement 12.10 gets summarised everywhere as "have an incident response plan ." That's true, but it undersells what an assessor actually checks — a single plan document doesn't evidence seven sub-requirements spanning 24/7 staffing, annual testing, risk-based training frequency, and a defined response to a very specific and often-missed scenario: stored account data turning up somewhere it was never supposed to be.

Does PCI DSS Require an Incident Response Plan?
aditi@cm-alliance.com (Aditi Uberoi)

