PCI DSS 4.0
Req 12: Information Security Policies

PCI DSS 4.0 12.10.6: 12.10.6 Plan evolved from lessons learned and industry developments

The security incident response plan must be changed and developed over time based on lessons learned and to reflect developments across the industry. The guidance adds that lessons-learned exercises should involve all levels of personnel and look at what worked as well as what did not; attacks on other organisations can also inform refinement. Customized approach objective: the plan's effectiveness and accuracy are reviewed and refreshed after each time it is invoked.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 42 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

NIST SP 800-53 Rev 5 · 5 controls

SOC 2 · 5 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC7.5 CC7.5 Recovering from security incidents

ISO 22301:2019 · 4 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 8.5 Exercise programme
  • 9.3.2 Management review input

ISO 27701:2019 · 3 controls

  • 5.8.2 Continual improvement
  • 6.13 Information security incident management
  • 6.13.1 Management of information security incidents and improvements
  • CFTC-SS-16 Security Incident Response Plan and Testing
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • ANSSI-HYG-40 Define a Security Incident Management Procedure

APRA CPS 234 · 1 control

  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • SEC10-BP08 Establish a framework for learning from incidents
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

C5 (Germany) · 1 control

CIS Controls v8 · 1 control

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • IR-4 Incident Handling

FedRAMP Moderate · 1 control

  • IR-4 Incident Handling

ISO 27001:2022 · 1 control

  • 5.27 Learning from information security incidents

ISO 27002:2022 · 1 control

  • 5.27 Learning from information security incidents

ISO/IEC 42001:2023 · 1 control

  • 10.1 Continual improvement

NIS2 Directive · 1 control

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 12: Information Security Policies

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 12.10.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 42 it maps to, and the evidence behind each claim, over MCP and REST.