PCI DSS Incident Response: The Legal Perspective #PCI

The SANS Institute InfoSec Reading Room recently published an article by Christian J. Moldes entitled PCI DSS and Incident Handling: What is required before, during and after an incident. Moldes’ whitepaper is a good starting point for developing an incident response plan to address payment card security breaches. The paper hits upon the key aspects of payment card security breach handling from an information security professional’s point of view. The paper, however, speaks little of the legal implications of a payment card security breach, and the incident response considerations that arise out of those implications.

via InfoSecCompliance.com – Technology, Privacy and Security Law & Risk Management » Blog Archive » PCI DSS Incident Response: The Legal Perspective.