r12.6 Automated incident response plan
Maintain an incident response plan that enables immediate response on suspicion or confirmation of an account data compromise, with detection, containment, and analysis capabilities on AWS.
AWS services
Requirement 12
Support Information Security with Organizational Policies and Programs
PCI sub-requirements covered
- 12.10 Suspected and confirmed security incidents are responded to immediately
How to implement on AWS
Document the response plan (roles, communication, escalation) and test it at least annually. Orchestrate playbooks with EventBridge, Lambda, and Step Functions from Security Hub/GuardDuty findings. Prepare forensic capabilities (Amazon Detective, isolated snapshots). Run simulation exercises (game days).
Practical implementation
How this control is implemented in each reference architecture:
Document and annually test an incident response plan; orchestrate playbooks with EventBridge/Lambda/Step Functions from GuardDuty/Security Hub findings and prepare forensic capabilities (Amazon Detective, isolated snapshots) in the account.
Single-account, 3-tier →Run incident response from the security tooling account with cross-account roles to contain and investigate in any CDE account; findings, playbooks, and forensics (Detective over central data) operate org-wide, and the plan is tested with game days.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine the incident response plan to verify it exists and includes all required elements, and review prior incidents to confirm the plan was followed (12.10.1.a, 12.10.1.b).
- Interview personnel and review documentation to verify the plan is reviewed/updated and tested at least every 12 months (12.10.2), that designated personnel are available 24/7 (12.10.3), and that monitoring/alert response is covered (12.10.5).
Evidence in AWS
- Documented incident response plan and evidence of its annual test.
- Automated playbooks (EventBridge/Lambda/Step Functions) and their history.
- Forensic capabilities enabled (Amazon Detective) and game-day records.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 12.10 — Suspected and confirmed security incidents that could affect the CDE are responded to immediately in accordance with a maintained and tested incident response plan.
Learning resources
- AWS Security Incident Response Guide (whitepaper)
References
- AWS Security Maturity Model: Incident response playbooks, Simulations
- PCI DSS v4.0.1 Requirement 12.10
PCI DSS Security Maturity Model