PCI DSS Security Maturity Model·AWS v1.0.0
Efficient Incident Response 👤 Customer

r12.6 Automated incident response plan

Maintain an incident response plan that enables immediate response on suspicion or confirmation of an account data compromise, with detection, containment, and analysis capabilities on AWS.

Quick Wins
Foundational
Efficient
Optimized
Effort: High Impact: High Applies to CDE: Yes

AWS services

AWS Security Hub Amazon GuardDuty Amazon Detective AWS Step Functions Amazon EventBridge

Requirement 12

Support Information Security with Organizational Policies and Programs

PCI sub-requirements covered

  • 12.10 Suspected and confirmed security incidents are responded to immediately

How to implement on AWS

Document the response plan (roles, communication, escalation) and test it at least annually. Orchestrate playbooks with EventBridge, Lambda, and Step Functions from Security Hub/GuardDuty findings. Prepare forensic capabilities (Amazon Detective, isolated snapshots). Run simulation exercises (game days).

Practical implementation

How this control is implemented in each reference architecture:

Document and annually test an incident response plan; orchestrate playbooks with EventBridge/Lambda/Step Functions from GuardDuty/Security Hub findings and prepare forensic capabilities (Amazon Detective, isolated snapshots) in the account.

Single-account, 3-tier →

Run incident response from the security tooling account with cross-account roles to contain and investigate in any CDE account; findings, playbooks, and forensics (Detective over central data) operate org-wide, and the plan is tested with game days.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterviewobserve

Testing procedures

  • Examine the incident response plan to verify it exists and includes all required elements, and review prior incidents to confirm the plan was followed (12.10.1.a, 12.10.1.b).
  • Interview personnel and review documentation to verify the plan is reviewed/updated and tested at least every 12 months (12.10.2), that designated personnel are available 24/7 (12.10.3), and that monitoring/alert response is covered (12.10.5).

Evidence in AWS

  • Documented incident response plan and evidence of its annual test.
  • Automated playbooks (EventBridge/Lambda/Step Functions) and their history.
  • Forensic capabilities enabled (Amazon Detective) and game-day records.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 12.10 — Suspected and confirmed security incidents that could affect the CDE are responded to immediately in accordance with a maintained and tested incident response plan.

Learning resources

References

  • AWS Security Maturity Model: Incident response playbooks, Simulations
  • PCI DSS v4.0.1 Requirement 12.10