In case of compromise
PCI DSS is a comprehensive standard that minimises the risk of data compromise.
However, security can never be perfect – it is therefore necessary to put an incident response plan in place, tailored to your own business environment.
If you experience or suspect a compromise at your business, it is vital that you take the following precautions:
- Contact Visa immediately
- Do not access or alter compromised systems, i.e. do not log on, or change passwords
- Do not turn the compromised systems off. Instead, isolate them from your network and unplug any network cables
- Preserve all logs and similar electronic evidence
- Perform a back-up of your systems to preserve their current state – this will also facilitate any subsequent investigations
- Log all actions taken