PCI DSS 12.10.4: Personnel responsible for responding to suspected and confirmed security incidents

PCI DSS v4.0.1 control 12.10.4: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.10.

Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.10

Personnel responsible for responding to suspected and confirmed security incidents are appropriately and periodically trained on their incident response responsibilities.

Summary

The people who respond to incidents are trained for it, and trained again periodically.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
12.10.4 Examine training documentation and interview incident response personnel to verify that personnel are appropriately and periodically trained on their incident response responsibilities.

Distinguish this from the general awareness programme in 12.6.1 and the annual training in 12.6.3. Those cover everybody. This is role-specific training for the responders, and the word "appropriately" ties the content to what each of them actually does: the person who triages the alert, the person who preserves evidence and the person who talks to the acquirer need different things. It works with 12.10.2, the annual test of the plan, which is a good vehicle for this training but is a separate control with a separate obligation, and with 12.10.4.1, which is where the frequency is decided.

What to prepare

  • The list of personnel with incident response responsibilities, matching the rota from 12.10.3.
  • What each was trained on and when, with the link to their role.
  • The training material itself, since "appropriately" is about content.
  • People available for interview, which the procedure requires.

How to implement it

1. Match the training to the role. Generic incident awareness for a team that includes the forensics contact and the person who notifies the card brands is training that leaves the specific parts untrained.

2. Use the annual test as the vehicle and record it as training. Running the plan is the most effective training there is, and 12.10.2 already requires it, so the marginal cost is the record.

3. Train the new joiners on arrival, not at the next cycle. Somebody added to the rota untrained is on call untrained.

4. Cover the parts that are not technical. Evidence preservation, who may speak externally and when the acquirer is notified are where an untrained response does lasting damage.

Where this commonly fails

  • Awareness training counted for responders, which covers everyone and prepares nobody in particular.
  • The rota and the trained list not matching, usually because someone joined the rota between cycles.
  • Training on tooling with nothing on the decisions: escalation, containment authority, external communication.
  • Records showing attendance without showing what was covered, so "appropriately" cannot be assessed.

Others in section 12.10:

Control What it requires
12.10.1 An incident response plan exists and is ready to be activated in the event of a suspected…
12.10.2 At least once every 12 months, the security incident response plan…
12.10.3 Specific personnel are designated to be available on a 24/7 basis to respond to suspected…
12.10.4.1 The frequency of periodic training for incident response personnel is defined in the entity’s…
12.10.5 The security incident response plan includes monitoring and responding to alerts from security…
12.10.6 The security incident response plan is modified and evolved according to lessons learned…
12.10.7 Incident response procedures are in place, to be initiated upon the detection of stored PAN…

12.10.3 · All controls · 12.10.4.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.