PCI DSS 4.0 12.10.5: 12.10.5 Plan covers alerts from security monitoring systems
The incident response plan must include monitoring of, and response to, alerts from security monitoring systems, covering at least: IDS and IPS (intrusion detection and prevention); network security controls; mechanisms detecting changes to critical files; the mechanism that detects changes and tampering on payment pages; and detection of unauthorised wireless access points. Applicability: the future-dated status applies only to the payment-page tampering bullet. Objective under the customized approach: alerts from monitoring and detection technologies are handled in a structured, repeatable way. Future-dated (payment-page bullet only): treated as a best practice up to 31 March 2025 and mandatory since then.
This control maps to 91 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 12.10.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.