FAQ #1448 Diff
What is meant by ?at risk? and ?at-risk timeframe? referenced in the Final PFI Report?
Earlier Version
Later Version
Removed
Added
The "At-Risk Timeframe" as identified in the Final PFI Report template, Appendix C refers to the period of time during the incident under investigation when data was vulnerable. For example, consider a scenario where evidence (e.g., system/access logs) indicates that an unauthorized entity breached the cardholder data
The at-risk timeframe is considered to have been from 6:30PM on April 14th when the breach occurred, through 7:15AM on April 17th when the breached system was taken offline (approximately 60 hours).
Further considering the scenario above, suppose the breached entity had several
would not date back to the oldest
only refers to the timeframe
For additional information please contact your case-specific Payment
Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.